A security policy is absent, and two of four workflow actions are unpinned. Recent work from five contributors, release notes, and clear licensing provide useful transparency.
85%
Total Score
100
100
88
50
The package is mature at 1650 days old and has a recent release, but only one release appeared in the last 12 months and the median interval is about 296 days, indicating a slow cadence.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, which makes vulnerability-reporting expectations less transparent for a production API module.
The workflow audit completed fully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, creating a limited reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/product Version ^6.0.0 | — | — |
spryker/merchant Version ^3.0.0 | — | — |
spryker/transfer Version ^3.42.0 | — | — |
spryker/shopping-list Version ^4.0.0 | — | — |
spryker/glue-application Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.