Documentation, tests, release notes, and a balanced five-person contributor base support dependable maintenance. The missing security policy and two unpinned workflow actions are modest process gaps, not evidence of abandonment.
86%
Total Score
100
100
88
50
The package has 23 releases over about 5 years, with a latest release in October 2025 and one release in the last 12 months. The slower recent registry cadence is partly compensated by current repository activity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest process gap, with no accompanying evidence of abandonment or unsafe behavior.
No repository security policy was found, which weakens vulnerability-reporting transparency, although active commits, tests, and organizational ownership provide compensating maintenance evidence.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/acl Version ^3.19.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/merchant Version ^3.13.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.