Package Health

spryker-sdk/app-sdk

Documentation, tests, release notes, and a clean install profile support dependable use. Organization backing and recent commits help, but concentrated ownership, unclear package-repository identity, and workflow pinning gaps warrant verification.

Latest 0.3.6PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

Two contributors were active, but one made 11 of 12 recent commits. That concentration creates a meaningful continuity risk despite the second contributor's activity.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although the artifact appears related to ACP, the collected evidence does not clearly establish that this repository belongs to this package.

Security policycaution

The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not by itself evidence of unsafe code.

Workflow auditcaution

The single workflow was fully analyzed with no trigger or audit findings, but all four action references are unpinned. Missing top-level permissions is acceptable here, while unpinned actions remain a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^5.3 || ^6.0.0 || ^7.0.0
—
—
composer/semver
Version ^3.0
—
—
symfony/console
Version ^5.3.0 || ^6.0.0 || ^7.0.0
—
—
spryker-sdk/spryk
Version ^0.4.0 || ^0.5.0
—
—
spryker-sdk/sync-api
Version ^0.1.8
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform