Tests, a changelog, and release notes make changes easier to evaluate. Workflow references are only partly pinned, while recent commits come from one contributor; organizational backing reduces the handoff risk.
76%
Total Score
67
100
50
One contributor made all commits in the last three months, concentrating recent activity in a single person. The organization-owned project provides some capacity to hand maintenance off.
Only one commit was recorded in the last three months, which indicates limited recent development activity. The recent registry releases and current repository push partly compensate for that narrow window.
No repository security policy was found. This is a transparency gap, although security scanning is present elsewhere in the collected evidence.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, four of six action references are unpinned, leaving avoidable supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/event Version ^2.4.0 | — | — |
spryker/kernel Version ^3.72.0 | — | — |
spryker/propel Version ^3.47.0 | — | — |
spryker/laminas Version ^1.0.0 | — | — |
spryker/symfony Version ^3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.