The package has a clear README and exact-version release notes. Organization ownership supports handoff, but the workflow needs tighter action pinning and the repository has no security policy.
70%
Total Score
67
100
50
One contributor, the release bot, made all 2 recent commits. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.
Only 2 commits were recorded in the last 3 months, indicating limited recent source activity. The recent release and organization backing partly offset this, but do not show broad maintenance activity.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, though it is not evidence of unsafe code.
The workflow audit was complete and found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings, but all 4 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/cart-note Version ^1.4.0 | — | — |
spryker/cart-note-merchant-sales-order-gui Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.