spryker/product 6.57.0 appears to be a mature, actively maintained package with a release history dating back to 2016, 132 releases, eight releases in the last 12 months, and a stable non-prerelease version. The artifact and repository contain substantial source code, tests, a changelog, a license file, and consistent package naming, while the repository is actively updated, unarchived, organization-owned, and supported by six recent contributors without strong contributor concentration. The main concerns are the absence of repository security scanning and a security policy, plus workflows without explicitly declared top-level token permissions; these are transparency and hardening gaps rather than evidence that the package is unfit to use.
88%
Total Score
100
100
94
80
Composer build tooling is present, but no security-scanning tools were detected. The missing security tooling is a transparency and hardening gap, though it does not by itself indicate poor maintenance.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
The sole workflow has no top-level permissions declaration. Although no top-level write permissions were observed, explicitly declaring least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.0.0 | — | — |
spryker/url Version ^3.16.0 | — | — |
spryker/event Version ^1.0.0 || ^2.3.0 | — | — |
spryker/store Version ^1.12.0 | — | — |
spryker/touch Version ^3.0.0 || ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.