This release appears healthy and suitable to depend on: it is a stable, non-deprecated 2.2.0 release with recent publication activity, an active unarchived repository, six commits from six maintainers in the last three months, and strong organization backing from Spryker. The package and repository are structurally consistent, include README and changelog documentation, and use a normal Composer build path without install-time lifecycle scripts. The main reservations are that neither the artifact nor repository contains tests, the repository has no declared security policy or security-scanning tooling, and its CI workflow does not declare top-level token permissions; these are meaningful hygiene gaps but do not outweigh the evidence of current maintenance and coherent ownership.
86%
Total Score
88
100
83
80
README and changelog documentation are present in both the package context and repository, but tests are absent from both. For a framework GUI module this is a real verification gap, though the documentation and repository-backed structure provide some compensation.
There were no new or closed issues and no pull requests in the last month; this gives little evidence of active community support. However, the absence of issue activity is partly offset by recent commits from multiple maintainers.
The repository has zero stars and forks and four watchers. This is weak community adoption evidence, but popularity is supporting evidence only and the organization-backed maintenance signals are more relevant here.
Composer is used as a build tool, but no security-scanning tools were detected. The standard build tooling is appropriate, while the missing security scanning is a repository hygiene gap.
No repository security policy was found. This reduces vulnerability-reporting transparency, although it is a hygiene concern rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/twig Version ^3.0.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/zed-ui Version ^4.3.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.