The repository lacks a security policy and automated security scanning, while two of four workflow actions are not pinned. Recent multi-contributor activity, organization backing, release notes, and a license file support continued maintenance.
76%
Total Score
100
100
88
83
Only three releases have appeared since August 2021, with one release in the last 12 months and a median interval of about 907 days. The recent 1.1.0 release provides some evidence of ongoing work, but the long cadence limits maturity confidence.
Composer build tooling is present, but no repository security-scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy or documented reporting path. This weakens security-maintenance transparency, though recent contributor activity provides some compensation.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, two of four action references are unpinned, leaving a small build-reproducibility gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.25.0 | — | — |
spryker/application Version ^3.0.0 | — | — |
spryker-shop/shop-ui Version ^1.54.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.