Clear licensing, tests, release notes, and a matching repository improve confidence. Two workflow actions are unpinned and no security policy is provided, but organizational backing and five active contributors limit the concern.
80%
Total Score
100
83
75
The registry shows four releases since September 2018 and no registry release in the last 12 months, which reduces release-cadence confidence. Recent repository activity provides some compensation but does not replace a current package release.
The repository has no security policy, leaving disclosure and response procedures undocumented. This is a transparency gap, though it is not evidence of unsafe code by itself.
Version 0.1.3 is not a stable-major release, so consumers should expect less API stability than from a 1.x package; it is not marked as a prerelease.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, leaving a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/company Version ^1.1.1 | — | — |
spryker/permission Version ^1.0.0 | — | — |
spryker/data-import Version ^1.3.0 | — | — |
spryker/company-role Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.