It includes tests, release notes, a license file, and a matching repository. Workflow hardening and security documentation are limited, but recent multi-contributor activity and organizational backing reduce abandonment concerns.
86%
Total Score
100
50
94
75
Thirteen runtime dependencies make the module part of a relatively broad framework dependency chain, adding some maintenance surface, but the profile is coherent for this Spryker integration module.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest supply-chain hygiene gap.
The repository has no published security policy, which reduces transparency for reporting and handling vulnerabilities.
The single workflow was fully analyzed with no injection or high-severity findings and no top-level write permissions; however, two of four action references are unpinned, weakening reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/store Version ^1.4.0 | — | — |
spryker/kernel Version ^3.37.0 | — | — |
spryker/storage Version ^3.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
spryker/util-encoding Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.