Tests, a changelog, and release notes make the package easy to assess, while organization ownership adds continuity. Four workflow actions are unpinned and no security policy is provided, leaving release hygiene weaker than the package structure suggests.
62%
Total Score
75
92
67
The latest release was about 16 months ago, and there were no releases in the last 12 months. The package has four releases over roughly two years, so maintenance appears to have slowed substantially.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, although the latest package release and its release notes show the project was previously maintained.
The linked repository has no security policy. For an integration module handling cloud-service access, this is a transparency gap, though the available tests and documented release process provide some compensation.
The single analyzed workflow has no untrusted checkout or script-injection findings, but all four action references are unpinned. That is a release-hygiene weakness rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/twig Version ^3.0.0 | — | — |
spryker/user Version ^3.16.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
aws/aws-sdk-php Version ^3.90.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.