Package Health

spryker-demo/merchant-review

The matching README, changelog, and organizational ownership provide useful project context, while the workflow audit found no high-risk behavior. All four workflow actions are unpinned and the repository has no security policy, so pin this exact version and reassess before upgrading.

Latest 1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This package has only one release, published 485 days ago, with no releases in the last 12 months. That leaves maintenance and compatibility direction uncertain despite the stable 1.0.0 version.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last 3 months. Its recent push date shows it is not archived, but current maintenance activity is still weak.

Security policycaution

The linked repository has no security policy, reducing transparency about vulnerability reporting and response. The repository's license, README, changelog, and working CI provide some compensating project documentation.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, but all 4 action references are unpinned. That is a supply-chain hygiene gap without evidence of an exploitable workflow path.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/kernel
Version ^3.75.0
spryker/locale
Version ^4.1.0
spryker/merchant
Version ^3.7.0
spryker/propel-orm
Version ^1.19.0
spryker/zed-request
Version ^3.19.0

Weekly Downloads

Info

Last Published
12 months ago
Created
12 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform