The package includes a usable README and release notes, with no install-time scripts or deprecation. All four workflow actions are unpinned, and recent commits come from one release bot; the missing security policy adds modest risk.
78%
Total Score
83
93
75
All three recent commits came from a single release bot, giving the project a concentrated recent commit base. Organization backing partly compensates for this, but the activity still provides limited evidence of independent maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no security policy, so there is no documented route for reporting vulnerabilities or explaining security handling.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/shipment Version ^8.28.0 | — | — |
spryker/shipment-gui Version ^3.3.0 | — | — |
spryker/shipment-type Version ^1.2.0 | — | — |
spryker-shop/shipment-page Version ^1.1.0 | — | — |
spryker/sales-shipment-type Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.