The README documents integration and a GitHub release records a small change. Organization backing helps offset the single registry maintainer, but repository security practices are thin.
58%
Total Score
67
81
75
The latest registry release was in March 2020, with no releases in the following six years. That long release gap materially raises abandonment and compatibility risk despite the package having eight releases overall.
There were no commits and no active maintainers in the measured three-month period. Combined with the old latest registry release, this points to weak current maintenance capacity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and oversight gap rather than evidence that the package is unsafe.
The repository has no published security policy. That limits disclosure guidance and is a genuine maintenance-transparency gap, though it is less significant than the inactive release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.0.0 | — | — |
spryker/customer Version ^7.10.2 | — | — |
spryker/glossary Version ^3.0.0 | — | — |
spryker/zed-request Version ^3.0.0 | — | — |
spryker-shop/checkout-page Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.