Testing and licensing are in place, but ongoing upkeep is limited. The workflow has no security findings, though its three unpinned actions and lack of repository security scanning reduce transparency.
58%
Total Score
75
100
88
75
The package has only one release, published about 2 years 8 months ago, with no releases in the last 12 months. This is meaningful evidence of limited ongoing maintenance.
There were no commits and no active maintainers in the last 3 months. Combined with the single-release history, this lowers confidence in ongoing maintenance.
The repository uses Make and Composer, but no security scanning tools were detected. That is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. For a connector package this is a transparency gap, although it is not severe on its own.
The sole workflow was fully analyzed with no reported audit findings and no dangerous triggers or untrusted checkouts. However, all three action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.