The package is straightforward to consume, with no install-time scripts and clear installation guidance. Its workflow audit found no high-risk patterns, though all four referenced actions are unpinned.
79%
Total Score
83
94
67
One contributor, the release bot, made all four recent commits, so direct recent contributor diversity is low. Organization ownership provides some ability to hand maintenance off, making this a caution rather than a severe abandonment signal.
The project uses Composer for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code.
The repository has no security policy. This limits published guidance for reporting and handling vulnerabilities, but it does not by itself indicate that maintenance has stopped.
The sole workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, leaving them exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/tax Version ^5.19.0 | — | — |
spryker/tax-storage Version ^1.8.0 | — | — |
spryker/tax-product-storage Version ^1.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.