Documentation and licensing are in place, and ownership is backed by an organization with several contributors. The long release interval and two unpinned workflow actions are modest maintenance and build-hygiene concerns.
81%
Total Score
100
88
50
The package has existed for about 6 years but only 1 release in the last 12 months, with a median interval of about 344 days. This suggests a slow cadence, partly offset by recent repository activity and a current release.
The repository uses Composer, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of unsafe code.
No repository security policy was found. That reduces disclosure transparency, although it is not by itself evidence of abandonment or a severe dependency risk.
The single workflow was fully analyzed with no audit findings, unsafe checkout, or script injection, but 2 of 4 action references are unpinned. The missing top-level permissions block is acceptable on its own, while partial pinning remains a small reproducibility concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/twig Version ^3.18.0 | — | — |
spryker/sales Version ^11.9.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.1.0 | — | — |
spryker-shop/shop-ui Version ^1.40.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.