The project has a long release history, recent releases, and a matching organization-owned repository. Maintenance is concentrated in one release bot, and all four workflow actions are unpinned; the missing security policy adds a smaller transparency gap.
72%
Total Score
67
50
94
67
Seven runtime dependencies make this a substantial feature integration rather than a minimal package, increasing dependency surface but not indicating an unhealthy profile on its own.
The organization-owned repository has only one contributor in the last three months, with that contributor responsible for all commits. Organizational backing provides some handoff capacity, but no second active contributor is shown.
Five commits were made in the last three months, but all activity came from one active maintainer, limiting evidence of distributed maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest assurance gap for a package with several runtime dependencies.
No repository security policy was found, reducing documented vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/agent Version ^1.10.0 | — | — |
spryker/agent-gui Version ^2.1.0 | — | — |
spryker-shop/agent-page Version ^1.25.0 | — | — |
spryker-shop/agent-widget Version ^1.4.0 | — | — |
spryker-shop/session-agent-validation Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.