The repository includes tests, a clear license, and organization backing, which support continued ownership. Unpinned workflow actions and no security policy leave avoidable maintenance and release-hygiene gaps.
60%
Total Score
75
88
50
The latest registry release was in January 2023, with no releases in the last 12 months and only three releases overall; this is a meaningful sign of slowing maintenance.
The repository had no commits and no active maintainers in the last three months. A push in January 2025 shows it is not entirely abandoned, but current activity remains weak.
The linked repository has no security policy, leaving reporting and response expectations undocumented. This is a transparency gap, though not evidence of a severe risk by itself.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/oms Version ^6.0.0 || ^7.0.0 || ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/sales Version ^5.0.0 || ^6.0.0 || ^7.0.0 || ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/payment Version ^3.0.0 || ^4.0.0 || ^5.0.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/checkout Version ^3.0.0 || ^4.0.0 || ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.