Documentation, tests, release notes, and a clean install profile support dependable use. Organization backing and recent commits help, but concentrated ownership, unclear package-repository identity, and workflow pinning gaps warrant verification.
68%
Total Score
83
92
67
Two contributors were active, but one made 11 of 12 recent commits. That concentration creates a meaningful continuity risk despite the second contributor's activity.
The repository name does not match the package name and its README does not mention the package. Although the artifact appears related to ACP, the collected evidence does not clearly establish that this repository belongs to this package.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not by itself evidence of unsafe code.
The single workflow was fully analyzed with no trigger or audit findings, but all four action references are unpinned. Missing top-level permissions is acceptable here, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.3 || ^6.0.0 || ^7.0.0 | — | — |
composer/semver Version ^3.0 | — | — |
symfony/console Version ^5.3.0 || ^6.0.0 || ^7.0.0 | — | — |
spryker-sdk/spryk Version ^0.4.0 || ^0.5.0 | — | — |
spryker-sdk/sync-api Version ^0.1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.