Package Health

spryker/company-roles-rest-api

This is a mature, actively maintained, non-deprecated stable release with a clear matching repository, organization backing, recent activity from five contributors, and coherent package structure. The package has a license file, changelog, build tooling, and no install-time lifecycle scripts or dangerous workflow patterns. The main reservations are the absence of repository tests and a security policy, lack of dedicated security scanning, and an undeclared top-level GitHub Actions token-permission policy; these are meaningful hygiene gaps but do not outweigh the strong maintenance and provenance evidence.

Latest 1.3.2PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The artifact has a README and changelog, and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. For a maintained API module this is a genuine verification gap, though the changelog and release process provide some compensating transparency.

Repo toolingcaution

The repository uses Composer build tooling, but no security-scanning tools were detected. Build support is present, while security-process coverage remains a hygiene gap.

Security policycaution

No repository security policy was detected. This lowers disclosure and vulnerability-response transparency, although it is a process gap rather than evidence of unsafe package behavior.

Token permissionscaution

The only workflow lacks top-level token permissions, and no read-only permissions declaration was detected. Explicit least-privilege configuration would provide stronger CI security assurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/kernel
Version ^3.30.0
—
—
spryker/symfony
Version ^3.0.0
—
—
spryker/transfer
Version ^3.42.0
—
—
spryker/company-role
Version ^1.13.0
—
—
spryker/uuid-behavior
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform