Healthy and suitable to depend on. It has a long release history, a recent stable release, active work from five contributors, and complete package and repository structure; the main gaps are no security policy or explicit workflow permissions and limited public popularity.
88%
Total Score
100
50
89
80
The package has 10 runtime dependencies, mostly related Spryker components and infrastructure libraries. This is a meaningful dependency surface but is coherent for an event module rather than unusually broad.
The repository has 0 stars and 1 fork, so public adoption evidence is limited. This is supporting evidence only and is outweighed by the package's long release history and current contributor activity.
Composer build tooling is present, but no security-scanning tool was detected. The absence of scanning is a transparency gap, though it is not by itself evidence of unsafe code.
The repository has no security policy. That weakens vulnerability-reporting transparency, although active maintenance and organization backing partly compensate for the gap.
The single workflow does not declare top-level token permissions and does not explicitly declare read-only permissions. No write permissions were detected, but explicit least-privilege configuration would be clearer.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.0.0 | — | — |
spryker/queue Version ^1.18.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/monolog Version ^2.0.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.