Organization ownership and a repository matching the package provide useful provenance. The absence of a security policy and four unpinned workflow actions leave notable maintenance and build-integrity gaps.
55%
Total Score
75
90
50
This release was published nearly six years ago, and it is the package's only registry release, with no releases in the last 12 months. That makes ongoing compatibility and maintenance uncertain despite the stable version.
The repository recorded zero commits and zero active maintainers in the last three months. A push in October 2024 shows it was not permanently abandoned, but current development activity is absent.
The linked repository has no security policy. That reduces transparency about how vulnerabilities are reported and handled, although the package is backed by an organization.
The single analyzed workflow is complete and has no reported dangerous findings, but all four action references are unpinned. This is a reproducibility and build-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/order-custom-reference Version ^1.0.0 | — | — |
spryker/order-custom-reference-gui Version ^1.0.0 | — | — |
spryker-shop/order-custom-reference-widget Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.