Recent activity is concentrated in one release bot, and all four workflow actions are unpinned. The package has a clear README, release notes for this version, no install-time scripts, and an audit found no dangerous workflow sinks.
78%
Total Score
67
94
75
One contributor, spryker-release-bot, made all 2 recent commits. Because the repository is owned by an organization, maintenance can be handed off, but the observed activity still shows no recent human contributor diversity.
Only 2 commits were recorded in the last 3 months, so recent source activity is limited. The recent release cadence and current repository push partly offset this concern.
Composer is used for the build, but no security-scanning tools were detected. The missing scanner is a modest transparency and assurance gap rather than evidence of abandonment.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it does not by itself indicate that the package is unsafe to depend on.
All 4 analyzed action references are unpinned, which weakens workflow reproducibility, but the audit found no untrusted checkout, script injection, dangerous trigger, or other findings. The workflow also has no top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product-set Version ^1.9.0 | — | — |
spryker/product-set-gui Version ^3.1.0 | — | — |
spryker/product-set-storage Version ^1.15.0 | — | — |
spryker-shop/product-set-widget Version ^1.11.0 | — | — |
spryker/product-set-page-search Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.