Package Health

spryker/cms-gui

Healthy and suitable to use. It has a long release history, frequent recent releases, active contributors, tests, and clear repository backing; the main caveats are missing security-policy and explicit workflow token-permission declarations.

Latest 5.21.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo popularitycaution

The repository has 0 stars and 1 fork, which offers little community-adoption evidence. This is only a supporting weakness because active releases, organization backing, and distributed recent contributions provide stronger maintenance evidence.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanning layer is a transparency and process gap, though it is not evidence that the package is unsafe.

Security policycaution

The repository has no security policy file. That leaves vulnerability-reporting and response expectations unclear, creating a modest transparency gap.

Token permissionscaution

The single analyzed workflow does not declare top-level token permissions. No write permissions were observed, but explicit least-privilege configuration would provide stronger workflow hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/cms
Version ^7.21.0
—
—
spryker/gui
Version ^3.48.0 || ^4.0.0 || ^5.5.0
—
—
spryker/url
Version ^3.5.0
—
—
spryker/twig
Version ^3.0.0
—
—
spryker/kernel
Version ^3.52.0
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform