Clear licensing, tests, release notes, and a balanced five-person contributor base support dependable maintenance. Security documentation is absent and half of workflow action references are unpinned, leaving moderate hygiene concerns.
83%
Total Score
100
88
75
The package has 30 releases since November 2019, but only one release in the last 12 months. Recent repository activity partly compensates for the slower registry cadence, so this is a modest maintenance concern.
Composer build tooling is present, but no repository security-scanning tool was detected. This is a hygiene gap, not evidence of abandonment or unsafe behavior by itself.
The repository has no published security policy, leaving disclosure and response expectations unclear for a package used in application infrastructure.
The sole workflow was fully analyzed with no reported audit findings or untrusted execution sinks, and it has no top-level write permissions. However, two of four action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/sales Version ^11.18.0 | — | — |
spryker/kernel Version ^3.33.0 | — | — |
spryker/merchant Version ^3.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
spryker/propel-orm Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.