The package includes release notes and a license file, and its workflow audit found no high-confidence problems. A missing security policy and only one release in the last 12 months leave modest transparency and cadence caveats.
84%
Total Score
100
88
50
The project has existed since July 2018 and released this version recently, but only one release appeared in the last 12 months. Active repository commits partly compensate for the slower registry cadence.
The repository uses Composer build tooling, but no security-scanning tool was detected. This is a modest hygiene gap rather than evidence of abandonment.
The repository has no published security policy, leaving reporting and response expectations less transparent for dependents.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/twig Version ^3.18.0 | — | — |
spryker/price Version ^5.3.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/currency Version ^3.4.0 || ^4.0.0 | — | — |
spryker-shop/shop-ui Version ^1.31.1 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.