This is a healthy, mature release with a long package history, a stable non-prerelease version, recent publication, an active non-archived organization-owned repository, multiple active contributors, and substantial source and test coverage. The package has no install-time lifecycle scripts, uses normal Composer build tooling, and its workflow shows no analyzed dangerous patterns. The main concerns are the absence of a repository security policy and explicit top-level workflow token permissions, plus low public popularity; these are transparency and hardening gaps rather than evidence of abandonment, and the organization backing and recent activity provide meaningful compensation.
88%
Total Score
88
100
89
80
There were no new or merged pull requests and no issue activity in the last month, which limits evidence of current collaboration; however, open pull requests are zero and recent commits are present.
The repository has 0 stars, 2 forks, and 8 watchers, indicating limited public popularity. Popularity is supporting evidence only, and the active organization-backed maintenance compensates for this weakness.
The repository uses Composer build tooling, but no security scanning tools were detected. The build setup is present, while security-tooling coverage is a modest hygiene gap.
No repository security policy was found. This reduces vulnerability-reporting transparency, though it is partly offset by the repository's active maintenance and organization ownership.
The only workflow lacks top-level token permissions, so its effective permission posture is less explicit than recommended. No top-level write permissions were detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/locale Version ^3.0.0 || ^4.0.0 | — | — |
spryker/propel Version ^3.46.0 | — | — |
spryker/product Version ^5.0.0 || ^6.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.