Tests, a changelog, and release notes make changes easier to verify. CI has no dangerous findings, but two of four actions are unpinned and the repository lacks a security policy.
86%
Total Score
100
94
67
The repository uses Composer build tooling, but no security scanning tools were detected; this is a modest transparency and maintenance gap, not a release blocker.
No repository security policy was found, leaving vulnerability reporting expectations unclear for a package that exposes API functionality.
The single workflow was fully analyzed with no dangerous audit findings and no broad write permissions, but two of four action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/store Version ^1.0.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.42.0 | — | — |
spryker/cms-storage Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.