Usable with caveats: the package is licensed, tested, stable, and backed by an organization, but it has had no release for over five years and no recent repository commits. Treat it as a maintenance-risk dependency rather than an actively maintained one.
58%
Total Score
50
100
83
75
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this indicates sustained inactivity and is the main adoption concern.
The package has seven releases and a relatively regular early release cadence, but its latest release was over five years ago and it has had no releases in the last 12 months. This materially raises staleness risk.
The repository has zero stars and forks and only two watchers, providing little supporting evidence of broad community use. Popularity is not required for health, but this offers no additional confidence for an otherwise dormant project.
Composer build tooling is present, showing basic project setup, but no security scanning tools were detected. The missing scanning is a hygiene gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. For a small framework extension this is a transparency gap, but the package has no other provided signal showing an active security response process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/category Version ^4.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.