The repository remains active, with five contributors making five commits in the last three months. Tests, changelog, release notes, licensing, and organization backing add useful transparency; the main gaps are no security policy and two unpinned workflow actions.
86%
Total Score
100
50
93
75
The module declares 12 runtime dependencies, including several closely related Spryker components; this is a substantial integration surface but coherent for a framework module.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest process gap.
The repository has no security policy, which weakens vulnerability-reporting transparency, although active maintenance and organization ownership partly compensate.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, so workflow supply-chain hygiene is incomplete but not severe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.7.0 | — | — |
spryker/kernel Version ^3.33.0 | — | — |
spryker/symfony Version ^3.1.0 | — | — |
spryker/transfer Version ^3.25.0 | — | — |
spryker/application Version ^3.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.