Documentation and release notes are present, and the organization-backed repository is active rather than archived. Single-contributor activity, no security policy, and four unpinned workflow actions warrant extra caution for long-term dependence.
68%
Total Score
67
94
75
One release bot made 100% of the three recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown.
Only three commits were recorded in the last three months, so recent maintenance is limited even though activity has not stopped.
Composer build tooling is present, but no repository security-scanning tool was detected, leaving security hygiene less visible.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no injection or high-confidence audit findings, and no top-level write permissions were used. However, all four action references are unpinned, which weakens build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/stock Version ^8.16.0 | — | — |
spryker/stock-gui Version ^3.1.0 | — | — |
spryker/availability Version ^9.32.0 | — | — |
spryker/merchant-stock Version ^1.4.0 | — | — |
spryker/availability-gui Version ^7.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.