The package includes a README, changelog, and release notes, with no install-time scripts. The workflow audit found no dangerous patterns, though two of four action references are unpinned.
82%
Total Score
100
86
67
Composer build tooling is present, but no security-scanning tool was detected; this is a minor transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy, leaving disclosure and response expectations undocumented; organizational backing partly offsets the concern but does not remove it.
Version 0.4.0 is not a stable major release, which signals a less mature compatibility promise, but it is not a prerelease and recent releases contain documented changes.
All workflows were analyzed with no dangerous audit findings, injection paths, or untrusted checkouts. Two of four action references are unpinned, a limited reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/merchant Version ^3.0.0 | — | — |
spryker/transfer Version ^3.42.0 | — | — |
spryker/merchant-product-offer-service-point-availability Version ^0.3.0 | — | — |
spryker/product-offer-service-point-availabilities-rest-api Version ^1.0.0 | — | — |
spryker/product-offer-service-point-availability-calculator-storage Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.