The MIT license, package README, and organization backing improve transparency. No security policy or recent issue activity provides little evidence of ongoing care.
38%
Total Score
75
70
50
Only two releases were published, both in October 2018, with no release in more than seven years. This is strong evidence of abandonment risk.
The repository has no open issues or pull requests and recorded no issue or pull-request activity in the last month. This is consistent with the package's long inactivity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a secondary concern rather than a standalone reason to reject the package.
Version 0.1.1 is not a stable major release, leaving greater API maturity and compatibility uncertainty alongside the very limited release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.0.0 | — | — |
spryker/glossary Version ^3.0.0 | — | — |
spryker/zed-request Version ^3.0.0 | — | — |
spryker/product-storage Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.