Healthy and suitable to use, with minor transparency gaps. It has a long release history, current repository activity from five contributors, complete package documentation and tests, and organization backing; the missing security policy and workflow permission declarations are the main caveats.
84%
Total Score
100
100
88
80
The package has existed for about 10 years with 66 releases and a latest release one day before collection. Only one release in the last 12 months suggests a slower recent cadence, but the current release and active repository partly compensate.
Composer is used as a build tool, but no security-scanning tools were detected. The absence of scanning is a hygiene gap, though it is not evidence of abandonment and other repository controls are present.
The repository has no security policy. This reduces transparency about vulnerability reporting and response, although the package has current commits and organization backing.
The single workflow has no top-level token permissions declaration and does not explicitly declare read-only permissions. No write permissions were detected, but the missing restriction is a workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.0.0 | — | — |
spryker/oms Version ^7.0.0 || ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/sales Version ^8.0.0 || ^10.0.0 || ^11.84.1 | — | — |
spryker/store Version ^1.16.0 | — | — |
spryker/guzzle Version ^2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.