Its README, release notes, and matching repository make it easy to understand and verify. All recent commits come from one release bot, and workflow actions are unpinned, leaving modest maintenance and build-reproducibility concerns.
78%
Total Score
67
100
50
One contributor, the release bot, made all 4 recent commits. Organization backing partly compensates for this concentration, but it still leaves limited visible contributor redundancy.
The repository recorded 4 commits in the last 3 months, showing recent activity, but that activity is limited in volume and does not demonstrate broad maintenance capacity.
The repository has no published security policy. This is a transparency gap, though it does not by itself indicate that the release is unsafe to depend on.
The single workflow has no untrusted checkout or script-injection findings, but all 4 action references are unpinned. The audit was complete, so this is a reproducibility and maintenance-hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product-option Version ^8.25.0 | — | — |
spryker/product-option-storage Version ^1.16.0 | — | — |
spryker-shop/product-option-widget Version ^1.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.