Clear installation guidance, release notes, and a stable release history improve confidence. Recent work is concentrated in one release bot, and all workflow actions are unpinned, leaving maintenance and build-integrity concerns.
68%
Total Score
67
94
75
One contributor made all three recent commits, creating a concentrated maintenance path. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.
Only three commits were recorded in the last three months, all from one active maintainer. Recent activity exists, but the low volume and concentration limit evidence of broad maintenance capacity.
Composer is used for builds, but no security-scanning tooling was detected. That is a modest transparency and assurance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a package with merchant-order functionality, this reduces clarity about vulnerability reporting and maintenance response.
The single workflow was fully analyzed with no injection or high-confidence audit findings, but all four action references are unpinned. The absence of a top-level permissions block is acceptable on its own; unpinned actions remain a build-integrity hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/oms Version ^11.54.0 | — | — |
spryker/sales Version ^11.83.0 | — | — |
spryker/sales-oms Version ^0.1.4 | — | — |
spryker/merchant-oms Version ^1.1.0 | — | — |
spryker/merchant-oms-gui Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.