Usable with caveats: it is a licensed, tested, non-deprecated package backed by an organization, but there has been no release or repository activity for about three years. Verify compatibility with your current Spryker stack before adopting it.
58%
Total Score
50
100
88
90
There were no commits and no active maintainers in the last three months, consistent with a repository that has been inactive since about three years ago. This is the strongest adoption concern.
Only one registry account has publishing access, creating some publishing bus-factor concern. This is partly mitigated by the package being backed by an organization-owned repository.
The latest release was about three years ago, with no releases in the last 12 months. This substantially lowers confidence that the package is actively maintained, despite its earlier regular release interval.
There are no open issues or pull requests, and no recent issue or pull-request activity. This may indicate stability, but alongside the lack of commits it also provides little evidence of ongoing maintenance.
The repository uses Composer, confirming a normal build tool for this PHP package, but it has no reported security-scanning tooling. The tooling gap is a modest transparency concern rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/cart Version ^2.0 || ^3.0 || ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
spryker-shop/shop-application-extension Version ^1.1 | — | — |
fond-of-spryker/enhanced-ecommerce-extension Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.