Usable with caveats: the package is licensed, tested, stable, and backed by a matching organization repository, but its latest registry release was about three years ago. Recent repository activity has also stopped, and the workflow lacks explicit token permissions and security scanning.
62%
Total Score
83
100
88
80
The package has only three releases and none in the last 12 months; its latest registry release was about three years ago, which raises maintenance and compatibility concerns despite the linked repository being updated later.
The repository recorded zero commits and zero active maintainers in the last three months, indicating currently inactive development and increasing abandonment risk.
The repository uses Make and Composer build tooling, but no security scanning tools were detected, leaving a security-maintenance gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response practices.
The only workflow does not declare top-level token permissions. Although no write permissions were explicitly observed, the missing declaration weakens workflow hardening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/api Version ^0.4.0 | — | — |
spryker/api-extension Version ^0.1.0 | — | — |
spryker/api-query-builder Version ^0.1.0 | — | — |
fond-of-oryx/thirty-five-up Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.