Testing, release notes, and balanced contributor activity add useful confidence. The project has no published security policy, and its release cadence is light, leaving modest transparency and maintenance concerns.
82%
Total Score
100
100
88
83
The package has existed for about five years and released once in the last 12 months, with a median interval of about 75 days. The latest release is recent, but the low recent release count suggests a lighter cadence.
Composer build tooling is present, supporting reproducible project workflows. No security scanning tool was detected, leaving some assurance coverage absent.
The linked repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself indicate that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.7.0 | — | — |
spryker/cart Version ^7.8.0 | — | — |
spryker/quote Version ^2.0.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/transfer Version ^3.25.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.