The linked repository is intact, matches the package, and documents this release with a changelog and release notes. Organization backing and a clean workflow audit do not offset the registry withdrawal and absent recent release activity.
15%
Total Score
75
67
50
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because future maintenance and support are not assured.
The package has 23 releases since 2018, but none in the last 12 months; its latest release was about 3 years ago. The earlier roughly 28-day median cadence does not compensate for the prolonged release gap.
The linked repository had no commits and no active maintainers in the last 3 months. This supports the evidence of current abandonment, despite a later recorded push in the repository metadata.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The package's organization backing provides some context but does not replace a published process.
The single workflow was fully analyzed with no dangerous findings or untrusted triggers, but all 4 action references are unpinned. That is a supply-chain hygiene gap, though no exploitable workflow path was identified.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/gui Version ^3.45.0 | — | — |
spryker/oms Version ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/cart Version ^5.0.0 || ^7.0.0 | — | — |
spryker/money Version ^2.0.0 | — | — |
spryker/offer Version ^0.1.0 || ^0.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.