The README, release notes, stable versioning, and organization ownership provide useful maintenance context. The small repository footprint and lack of a security policy leave less transparency for long-term evaluation.
68%
Total Score
63
100
94
50
One contributor made all two recent commits, concentrating short-term activity in a single release bot; organization ownership provides some handoff capacity but does not show active human diversity.
Only two commits were recorded in the last three months, so ongoing development activity is modest despite the recent release.
No pull requests were merged in the last month and no new issues or pull requests were recorded; this is a limited activity signal, but the recent release provides compensating evidence.
Composer is used for builds, but no security scanning tool was detected, leaving a meaningful supply-chain hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product Version ^6.56.0 | — | — |
spryker/product-offer Version ^1.18.0 | — | — |
spryker/product-offer-gui Version ^2.2.0 | — | — |
spryker/product-offer-storage Version ^1.12.0 | — | — |
spryker/merchant-product-offer Version ^1.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.