The package has a clear README, release notes for this version, recent publication, and organizational backing. Its workflow references are not pinned, and recent commits come from one release bot, so maintenance resilience and build reproducibility are weaker than the release cadence suggests.
78%
Total Score
67
100
94
75
All 3 recent commits came from one contributor, the spryker-release-bot. Organizational ownership provides some handoff capacity, but no second active contributor is shown in this period.
The repository recorded 3 commits in the last 3 months, showing recent activity, but that is a light maintenance pace for a dependency. The current release partly offsets this concern.
Composer is used for builds, but no security scanning tools are reported. This is a modest transparency and monitoring gap rather than evidence of unsafe behavior.
The repository has no security policy file. For a maintained package this reduces published guidance for reporting and handling vulnerabilities.
The single workflow was fully analyzed with no trigger, injection, or high-confidence audit findings, and it has no top-level write permission. However, all 4 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/weekday-schedule Version ^1.1.0 | — | — |
spryker/merchant-opening-hours Version ^1.0.0 | — | — |
spryker/merchant-opening-hours-storage Version ^1.2.0 | — | — |
spryker-shop/merchant-opening-hours-widget Version ^1.0.0 | — | — |
spryker/merchant-opening-hours-data-import Version ^0.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.