The README, recent release, and organization ownership provide useful context for adoption. A single active contributor, no security policy or scanning, and four unpinned workflow actions leave maintenance and build-hygiene concerns.
74%
Total Score
67
93
50
One contributor made all 2 recent commits, concentrating operational knowledge. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, with activity from 1 maintainer. The recent release cadence partly offsets this, but current development activity is thin.
Composer is used for builds, but no security-scanning tools were detected. This is a modest transparency and assurance gap rather than evidence of an unsafe release.
The repository has no security policy. For a maintained organization-owned package this weakens vulnerability-reporting transparency, although it does not indicate abandonment by itself.
The workflow audit completed successfully with no injection or high-severity findings, but all 4 action references are unpinned. The workflow has no top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product Version ^6.56.0 | — | — |
spryker/product-search Version ^5.28.0 | — | — |
spryker/product-storage Version ^1.56.0 | — | — |
spryker/merchant-product Version ^1.12.0 | — | — |
spryker/product-validity Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.