The small package has clear installation guidance and release notes for this version. Its workflow is fully analyzed but uses four unpinned actions, while the missing security policy and concentrated commits leave modest maintenance risk.
78%
Total Score
75
100
50
All two recent commits came from one release bot, so observed activity is highly concentrated. Organization ownership provides some handoff capacity, but the collected activity still leaves a modest maintenance risk.
The repository has no security policy, which weakens disclosure transparency. This is a limited concern because the package is actively released and the repository is organization-backed.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or excessive permissions, but all four action references are unpinned. That creates a supply-chain hygiene gap without evidence of an actively dangerous workflow.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/multi-cart Version ^1.17.0 | — | — |
spryker-shop/multi-cart-page Version ^2.9.0 | — | — |
spryker-shop/multi-cart-widget Version ^1.11.0 | — | — |
spryker/multi-cart-data-import Version ^0.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.