This is a healthy, actively maintained release from an organization-backed repository. It has a stable non-prerelease version, recent publishing activity, an unarchived and correctly matching source repository, five active contributors with evenly distributed recent commits, a changelog, license file, and no install-time lifecycle scripts or dangerous workflow patterns. The main reservations are the modest release cadence, absence of repository security scanning and a security policy, and an undelared top-level GitHub Actions token permission policy; these are hygiene gaps rather than evidence of abandonment. The package appears reasonable to depend on, subject to normal review of its proprietary licensing and runtime dependency chain.
84%
Total Score
100
100
89
80
The artifact has a README and changelog, and the repository uses GitHub Releases, which supports release transparency. Tests are absent in both the artifact and repository, a modest assurance gap for a UI module, but not by itself evidence of poor maintenance.
Composer is used as a build tool, providing expected ecosystem tooling. No security scanning tools were detected, which is a security-hygiene gap, though it does not establish abandonment or unsafe behavior by itself.
No repository security policy was found. This reduces vulnerability-reporting transparency, but the gap is not severe enough to outweigh the active organization-backed maintenance evidence.
The sole workflow does not declare top-level token permissions, so least-privilege intent is not explicit. It has no top-level write permissions, making this a workflow-hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/twig Version ^3.0.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/zed-ui Version ^4.3.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.