The repository is not archived, has tests and release notes, and the package has no install-time scripts. Missing a security policy and two unpinned workflow actions are modest transparency and build-hygiene gaps.
88%
Total Score
100
50
94
83
The package declares 15 runtime dependencies, reflecting a broad framework integration surface; this adds maintenance coupling but is consistent with the module's substantial Spryker functionality.
Composer build tooling is present, but no repository security scanning tools were detected; this is a modest process gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow was fully analyzed with no audit findings, no untrusted checkouts, and no script injection, but 2 of 4 action references are unpinned, leaving some build reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/store Version ^1.4.0 | — | — |
spryker/kernel Version ^3.33.0 | — | — |
spryker/propel Version ^3.47.0 | — | — |
spryker/product Version ^5.5.0 || ^6.0.0 | — | — |
spryker/storage Version ^3.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.