Package Health

spryker-sdk/integrator

This release appears healthy to depend on: it is actively released, was updated very recently, is not deprecated or archived, has substantial package and repository scaffolding, and shows recent activity from two contributors within an organization-owned project. The main reservations are the relatively small repository audience, absence of a declared security policy, and workflows that do not declare top-level token permissions; these are transparency and hardening gaps rather than evidence of abandonment. The proprietary license is accompanied by a LICENSE file, so licensing is explicit, although dependency suitability should be confirmed for the consuming project.

Latest 0.2.8PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 14 runtime dependencies, including Composer, AWS SDK, Symfony components, and parsing/process libraries. This is a moderately broad dependency surface for an integration and migration tool, creating some maintenance coupling but not an inherently unhealthy profile.

Repo popularitycaution

The repository has only 3 stars, 5 forks, and 11 watchers, so external adoption evidence is limited. Popularity is supporting evidence rather than a verdict, and the recent release and commit activity provide stronger maintenance evidence.

Repo toolingcaution

The repository uses Composer as a build tool, but no security-scanning tooling was detected. The missing automated security scanning is a hardening gap, though it does not by itself indicate abandonment or unsafe maintenance.

Security policycaution

No SECURITY.md or equivalent security policy was found. That reduces transparency around vulnerability reporting and response expectations, with no provided compensating security-policy evidence.

Token permissionscaution

All three workflows lack top-level token permission declarations, which leaves workflow permissions less explicit than recommended. No workflow has top-level write permissions, so this is a hardening caution rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^6.4 || ^7.0
aws/aws-sdk-php
Version ^3.368.0
symfony/console
Version ^6.4 || ^7.0
symfony/process
Version ^6.4 || ^7.0
nikic/php-parser
Version ^5.7.0

Weekly Downloads

Info

Last Published
18 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform