This is a healthy, actively maintained release from an organization-backed repository. It has a stable 2.4.0 release, seven releases in the last 12 months, recent repository activity with six contributors, matching repository identity, tests, changelog, license file, and no install-time lifecycle scripts or registry deprecation. The main cautions are that the repository has no declared security scanning, no security policy, and its CI workflow lacks top-level token permissions; these reduce transparency and workflow hardening but do not outweigh the strong maintenance and packaging evidence.
88%
Total Score
100
100
94
80
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a transparency and hygiene gap, though it is partly mitigated by the presence of CI and other repository tooling.
The repository has no SECURITY.md or other declared security policy, which leaves vulnerability-reporting and security-maintenance expectations less transparent.
The one CI workflow lacks top-level token permissions and does not declare read-only permissions. Although no write permissions were detected, explicit least-privilege configuration would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/user Version ^3.27.0 | — | — |
spryker/kernel Version ^3.52.0 | — | — |
spryker/router Version ^1.15.0 | — | — |
spryker/zed-ui Version ^4.3.0 | — | — |
spryker/session Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.