The package includes a README, changelog, release notes, and no install-time scripts. Its workflow has two unpinned actions and the repository lacks a security policy, but there are no audited workflow findings or concentrated ownership concerns.
82%
Total Score
100
100
88
67
The package has only three releases over roughly six years, with a median interval of about three years, which indicates a sparse release history despite a release in the last 12 months.
The repository uses Composer, but no security-scanning tools were detected; this is a modest supply-chain hygiene gap rather than evidence of abandonment.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.
The single workflow was fully analyzed with no findings, no untrusted checkout or script-injection paths, and no top-level write permissions. Two of four action references are unpinned, a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/barcode Version ^1.0.0 | — | — |
spryker-shop/shop-ui Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.