Healthy and suitable to depend on. It has a long release history, a current stable release, active work from five contributors, and strong package and repository documentation; the main caveats are limited security-process transparency and permissive workflow defaults.
88%
Total Score
100
100
89
80
The repository has zero stars and one fork, which offers little community adoption evidence; popularity is supporting evidence only and is outweighed here by organizational backing and active maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency gap, though it is partly offset by the active organization-backed repository and clean workflow analysis.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
The sole workflow has no top-level token permissions declaration. No write permissions were observed, but explicitly declaring least-privilege permissions would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/cart Version ^5.12.0 || ^7.5.0 | — | — |
spryker/quote Version ^2.22.0 | — | — |
spryker/store Version ^1.9.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/customer Version ^6.0.0 || ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.