Recent releases and an active organization-backed repository provide useful maintenance evidence. Pin the four workflow actions and consider adding security scanning before adopting this release in a sensitive project.
72%
Total Score
67
94
50
One contributor made all 3 commits in the last 3 months, creating concentrated activity. The organization-owned repository provides some handoff capacity, so this is a concern rather than a severe risk.
There were 3 commits in the last 3 months, showing recent activity, but the pace is modest for an actively maintained project. The recent release history partly compensates for that limited commit volume.
Composer build tooling is present, but no security-scanning tools were detected. That weakens automated assurance without indicating abandonment by itself.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it does not by itself show that the release is unsafe.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or high-severity audit findings. However, all 4 action references are unpinned, leaving build inputs less reproducible and harder to control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product-offer-service-point-availability Version ^1.0.0 | — | — |
spryker/product-offer-service-point-availability-storage Version ^1.1.0 | — | — |
spryker-shop/product-offer-service-point-availability-widget Version ^1.3.0 | — | — |
spryker/product-offer-service-point-availability-calculator-storage Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.