Documentation, tests, and release notes are included, with a clear package layout and no install-time scripts. The repository is owned by an organization, has recent activity from five contributors, and shows no workflow findings; two unpinned actions and no security policy are minor weaknesses.
86%
Total Score
100
86
67
The package has existed since 2018 and released version 1.3.2 recently, but only one release occurred in the last 12 months and the median interval is about 254 days. This suggests deliberate rather than rapid maintenance and is a minor concern, not an abandonment signal.
The project uses Composer, but no security scanning tools were detected. That is a transparency and hygiene gap, though the repository otherwise has active maintenance and testing evidence.
No repository security policy was found. This weakens vulnerability-reporting transparency, but it is a minor concern alongside the package's active, organization-backed development.
All workflows were analyzed with no audit findings, unsafe checkout, or script-injection findings. Two of four action references are unpinned, which is a minor reproducibility weakness; the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/store Version ^1.19.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/locale Version ^3.0.0 || ^4.0.0 | — | — |
spryker/product Version ^6.2.0 | — | — |
spryker/product-label Version ^2.5.0 || ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.