The package includes a license file, README, changelog, and release notes. Its workflow audit found no risky findings, though two of four action references are unpinned and no security policy is published.
76%
Total Score
100
100
83
83
Only two releases exist, with no registry release in the last 12 months and an interval of about 5 years between releases; this is a meaningful maturity and cadence concern, partly offset by recent repository activity.
The repository has no stars or forks and only three watchers, offering little community validation; this is supporting evidence only and does not outweigh the active organization-backed maintenance.
Composer build tooling is present; no security scanning tools were detected, which is a modest process gap for a maintained package.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities.
The single workflow was fully analyzed with no untrusted checkouts, script injections, or audit findings. Two of four action references are unpinned, but there are no broad top-level write permissions or dangerous triggers.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.33.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
spryker/price-product-storage Version ^2.9.0 || ^4.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.