Recent releases and an active organization-backed repository support continued maintenance. All four workflow actions are unpinned, and the latest three months show only two commits from one release bot with no security policy, leaving meaningful maintenance and build-hygiene gaps.
72%
Total Score
67
94
67
All 2 recent commits came from one release bot, giving the repository a concentrated recent commit base; organization backing helps with handoff capacity but no second active contributor is shown.
The repository had 2 commits in the last 3 months, showing some recent activity but a modest maintenance pace for a dependency.
Composer is used for builds, but no security scanning tools were detected, leaving repository security hygiene less visible.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
The single workflow was fully analyzed with no trigger or audit findings, and it does not use broad top-level write permissions. However, all 4 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/mail Version ^4.13.0 | — | — |
spryker/newsletter Version ^4.7.0 | — | — |
spryker/symfony-mailer Version ^1.5.0 | — | — |
spryker-shop/newsletter-page Version ^1.3.0 | — | — |
spryker-shop/newsletter-widget Version ^1.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.