This release appears healthy and suitable for dependency use: it has a long release history dating back nearly 9.5 years, six releases in the last 12 months, stable versioning, an active and unarchived organization-owned repository, recent commits from seven contributors, and strong package and repository scaffolding including tests, changelog, CI configuration, and a license file. The main reservations are the absence of a repository security policy and explicit GitHub Actions token permissions, plus no configured security-scanning tool; these are transparency and workflow-hardening gaps rather than evidence of abandonment. Low star and fork counts provide little independent popularity support, but active maintenance and broad recent contribution are more relevant here.
88%
Total Score
100
100
89
80
The repository has zero stars and forks and 35 watchers, so popularity offers limited external validation. This is only a supporting weakness because active release and contributor signals are stronger evidence of maintainability.
Composer build tooling is present, but no security-scanning tool was detected. The build setup supports reproducibility, while the missing scanner is a modest supply-chain hygiene gap.
The repository has no security policy. This reduces vulnerability-reporting transparency, although it is not evidence that the package is unmaintained.
The one workflow lacks top-level token permissions, so least-privilege intent is not explicitly declared. No top-level write permissions were found, limiting the severity of this workflow-hardening gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
propel/propel Version ^2.0.0 | — | — |
spryker/config Version ^3.0.0 | — | — |
spryker/kernel Version ^3.67.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/error-handler Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.