This is a mature, actively maintained Spryker organization package with a release history spanning over 8 years, 40 releases, and 9 releases in the last 12 months. The repository is active, unarchived, correctly matched to the package, and has five active contributors with relatively distributed recent commits; the package also has a changelog, license file, CI workflow, and no install-time lifecycle scripts. The main concerns are the absence of repository tests and a security policy, plus workflow token permissions that are not explicitly constrained and no detected security-scanning tooling. These are meaningful transparency and security-hygiene gaps, but they do not outweigh the strong maintenance, backing, release cadence, and repository evidence.
86%
Total Score
100
100
89
80
The package includes a README and changelog, and the repository also uses GitHub Releases, providing basic consumption and release documentation. Neither the artifact nor repository contains tests, which is a maintenance and verification gap for a library package.
Composer build tooling is present, supporting reproducible package management, but no security-scanning tooling was detected. The missing security automation is a modest repository-hygiene concern.
The repository has no security policy. This reduces transparency for vulnerability reporting and response expectations, although it is a process gap rather than evidence of unsafe package behavior.
The only workflow lacks top-level token permissions, and no read-only permissions declaration is shown. Although no top-level write permission was detected, explicitly restricting workflow tokens would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/store Version ^1.4.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.19.0 | — | — |
spryker/transfer Version ^3.42.0 | — | — |
spryker/container Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.