The project includes tests, release notes, a matching repository, and clear licensing. Its long release gap and absent recent commit activity reduce confidence in ongoing maintenance; the missing security policy and unpinned workflow actions add smaller hygiene concerns.
55%
Total Score
75
88
67
The package has had no registry release in more than four years, despite 13 releases overall. Its earlier release cadence shows a previously established project, but the extended gap raises abandonment risk.
There were zero commits and zero active maintainers in the last three months. The repository was pushed in October 2024, but the lack of current activity materially increases maintenance risk.
Composer build tooling is present, but no security scanning tools were detected. The build setup is clear, while security-maintenance visibility is limited.
The repository has no security policy. For a payment integration, this is a meaningful transparency gap because users have no documented reporting path in the collected evidence.
The single workflow was fully analyzed with no injection or high-severity findings, but all seven action references are unpinned. This leaves avoidable workflow supply-chain hygiene risk; the missing top-level permissions block is not harmful on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/gui Version ^3.0.0 | — | — |
spryker/money Version ^2.0.0 | — | — |
spryker/quote Version ^2.0.0 | — | — |
spryker/sales Version ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/config Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.