Healthy and suitable to depend on. It has a long release history, a recent stable release, active contributors, comprehensive tests and documentation, and clear organizational backing; the main gaps are missing security scanning and a security policy.
90%
Total Score
100
100
94
80
Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while security-process coverage is a genuine hygiene gap.
No repository security policy was found. For a framework module handling agent authentication and multi-factor-authentication integrations, this is a transparency gap, although active maintenance and repository tests provide some compensation.
The one workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege settings would provide stronger workflow hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10954 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. spryker-shop/agent-page is vulnerable to Auth Bypass in versions 1.18.0 - 1.21.1. | 1.18.0 - 1.21.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.17.0 | — | — |
spryker/agent Version ^1.11.0 | — | — |
spryker/quote Version ^2.0.0 | — | — |
spryker/store Version ^1.19.0 | — | — |
spryker/kernel Version ^3.52.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.