Documentation and packaging are straightforward, and the project has continued releasing. All four workflow actions are unpinned, while recent commits come from one contributor; organizational ownership helps, but maintenance remains concentrated.
72%
Total Score
67
100
50
One contributor, the release bot, accounts for all recent commits, creating concentrated maintenance capacity; organization ownership provides some handoff potential but does not show a second active contributor.
Only 2 commits were recorded in the last 3 months, so recent maintenance activity is light; the current release provides some compensating evidence of ongoing work.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap, not evidence of an active security problem.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 4 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/merchant-product-offer-service-point-availability Version ^0.3.0 | — | — |
spryker-shop/merchant-product-offer-service-point-availability-widget Version ^0.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.