Workflow hygiene needs tightening, with 30 of 32 action references unpinned and a high-confidence unpinned container image; inherited secrets add exposure. The repository is organization-backed and actively developed, but its name and README do not identify this package directly.
76%
Total Score
100
50
94
67
The package declares 239 runtime dependencies and 28 development dependencies, creating substantial upgrade and transitive-maintenance burden for adopters.
post-install-cmd and post-update-cmd scripts run during dependency operations, adding operational and supply-chain exposure, although this is not by itself evidence of abandonment.
The linked repository is named b2c-demo-shop rather than spryker-shop/suite, and its README does not mention this package. That leaves some uncertainty that the repository is the exact source for this package.
The repository has no SECURITY.md or other declared security policy, leaving vulnerability reporting and response guidance unclear.
All 10 workflows were analyzed with no failed files or untrusted-checkout/script-injection findings, but 30 of 32 uses are unpinned, one high-confidence finding flags an unpinned container image, and high-confidence secrets-inherit findings widen credential exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/uuid Version ^1.0.1 | — | — |
galbar/jsonpath Version ^1.3.1 | — | — |
spryker/sitemap Version ^1.0.0 | — | — |
spryker/tax-app Version ^0.4.3 | — | — |
spryker/chart-gui Version ^1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.