This is a healthy, actively maintained release from an organization-backed repository. The package is stable, not deprecated, recently updated, has a matching repository with a documented package reference, and shows five commits from five contributors in the last three months, indicating good maintenance distribution. The artifact includes a README, changelog, license file, and substantial source tree, with no install-time lifecycle scripts or dangerous workflow patterns. The main reservations are the absence of repository tests, lack of a security policy, and no top-level GitHub Actions token-permission declaration; these are transparency and CI-hardening gaps, but they do not outweigh the strong evidence of active organizational maintenance.
86%
Total Score
100
100
88
80
A README and changelog are present and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. The missing tests are a modest maintenance-confidence gap for a substantial module.
Composer build tooling is present, but no security-scanning tool was detected. This is a CI hygiene gap, though other workflow signals show no dangerous patterns.
The repository has no security policy. This reduces vulnerability-reporting transparency, although it is not evidence that the package is unmaintained.
The single workflow lacks a top-level token-permissions declaration and does not explicitly declare read-only permissions. This weakens CI least-privilege hygiene, despite no top-level write permissions being observed.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/zed-ui Version ^4.3.0 | — | — |
spryker/comment Version ^1.4.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.