A security policy and repository security scanning are absent, while the package has a README and release notes. Organization backing and recent publication provide some continuity.
68%
Total Score
67
93
67
One release-bot contributor accounts for all recent commits. Organization backing provides some maintenance capacity, but the observed activity remains highly concentrated.
Only two commits were recorded in the last three months, so observed development activity is light despite the recent release.
Composer is used for builds, but no repository security scanning tool was detected, leaving a security-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, or audit findings, but all four referenced actions are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/data-import-merchant Version ^1.0.0 | — | — |
spryker/data-import-merchant-portal-gui Version ^2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.