License coverage is clear, and the small package surface keeps integration straightforward. The workflow’s four unpinned actions and absent security policy leave modest maintenance and build-transparency caveats.
72%
Total Score
67
100
75
One contributor, spryker-release-bot, made all two recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown, leaving concentration risk.
Only two commits were recorded in the last three months, so activity is present but light and provides limited evidence of broad ongoing development.
The linked repository has no security policy, reducing transparency about how vulnerabilities are reported and handled.
The sole workflow was fully analyzed with no injection findings, dangerous triggers, or excessive top-level permissions. However, all four action references are unpinned, which leaves build inputs less reproducible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product-barcode Version ^1.1.0 | — | — |
spryker/product-barcode-gui Version ^1.5.0 | — | — |
spryker-shop/product-barcode-widget Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.