The artifact includes tests, a changelog, a README, and no install-time scripts. Its proprietary license and 22 runtime dependencies may limit reuse and increase integration cost.
12%
Total Score
50
40
100
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe adoption and abandonment risk for a dependency.
The package is about 18 months old but has had no releases in the last 12 months; its latest release was 0.6.0 on June 12, 2025. This strongly suggests stalled maintenance.
The package declares 22 runtime dependencies across multiple Spryker components, creating a broad compatibility surface and higher integration cost. The profile is not inherently unsafe, but it adds caution for an abandoned package.
The manifest declares a proprietary license and the artifact contains a LICENSE file, so licensing is explicit rather than missing. However, proprietary terms can restrict reuse and redistribution.
Version 0.6.0 is not a stable major release, so API compatibility may remain limited. The absence of recent releases compounds that maturity concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/gui Version ^3.60.0 | — | — |
spryker/sales Version ^11.0.0 | — | — |
spryker/kernel Version ^3.75.0 | — | — |
spryker/symfony Version ^3.18.0 | — | — |
spryker/util-text Version ^1.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.