Organization backing, a complete source tree, and a stable 1.0.0 release provide useful transparency. The lack of recent commits and missing security controls make long-term maintenance less reassuring.
58%
Total Score
75
100
88
80
This package has only one release, published about 12 months ago, so there is little release history to demonstrate sustained maintenance.
There were no commits and no active maintainers in the last three months, which is a meaningful sign of limited recent maintenance for a package released about a year ago.
The repository uses Composer, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The only workflow lacks top-level token permissions, so its permissions are not explicitly constrained at the workflow level.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/sales Version ^11.40.5 | — | — |
spryker/kernel Version ^3.75.0 | — | — |
spryker/product Version ^6.37.0 | — | — |
spryker/shipment-extension Version ^1.2.0 | — | — |
spryker/merchant-sales-order Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.