AgentSecurityMerchantPortalGui module
88%
Total Score
100
100
89
80
The repository has zero stars and forks and four watchers, which provides little external validation; this is only a supporting caution because organizational backing and active development are present.
Composer build tooling is present, but no security-scanning tools were detected; this leaves a modest repository hygiene gap for a security-related module.
No repository security policy was found, leaving vulnerability-reporting guidance undocumented; active maintenance and CI provide only partial compensation.
The CI workflow has no top-level token-permissions declaration and does not explicitly declare read-only access, so its permission boundary is less transparent than it should be.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10951 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. spryker/agent-security-merchant-portal-gui is vulnerable to Auth Bypass in versions 1.3.0 - 1.4.0. | 1.3.0 - 1.4.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.17.0 | — | — |
spryker/user Version ^3.32.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/zed-ui Version ^4.3.0 | — | — |
spryker/session Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.