The package has a clear repository, license, README, changelog, and organization backing. Workflow references are all unpinned, and the repository has no security policy or scanning tools, adding maintenance and build-hygiene concerns.
58%
Total Score
75
100
81
83
The package includes a README and changelog, and the repository has a changelog and uses GitHub releases. Missing tests in the published artifact are normal packaging practice, while the repository's lack of tests is a modest maturity limitation.
This package has made only one release, on 22 May 2025, with no releases in the last 12 months. That is limited evidence of ongoing maintenance for a package now about 16 months old.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is the strongest indication of limited current maintenance.
Composer build tooling is present, but no security scanning tools are reported. This leaves an avoidable transparency and assurance gap without proving the package is unsafe.
The repository has no security policy. That makes vulnerability reporting and response expectations less transparent for dependents.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/acl Version ^3.13.0 | — | — |
spryker/user Version ^3.14.1 | — | — |
spryker/queue Version ^1.9.3 | — | — |
spryker/kernel Version ^3.75.0 | — | — |
spryker/propel-orm Version ^1.19.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.