The README explains installation and dependencies clearly. Release notes and a licensed artifact support transparent consumption, while the small dependency set keeps integration focused.
78%
Total Score
75
100
94
67
Only 2 commits were recorded in the last 3 months, showing limited recent repository activity, although the recent release history provides some compensating evidence.
Composer is used for builds, but no security-scanning tools were detected, leaving a modest verification gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 4 referenced actions are unpinned, which is a workflow supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/picking-list Version ^1.3.0 | — | — |
spryker/picking-list-push-notification Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.