The package includes tests, documentation, release notes, and a clear source tree. Workflow hardening and the absent security policy leave modest transparency and reproducibility gaps.
88%
Total Score
100
100
88
83
Composer build tooling is present, but no security scanning tools were detected, leaving a modest automated security-coverage gap.
The repository has no published security policy, which makes vulnerability-reporting expectations less transparent despite other evidence of active maintenance.
Version 0.3.1 is not a prerelease and recent releases have no prerelease share, though the pre-1.0 major version signals some API maturity risk.
The only workflow was fully analyzed with no audit findings or untrusted execution paths. However, 2 of 4 action references are unpinned, a minor reproducibility and update-integrity gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.42.0 | — | — |
spryker/zed-request Version ^3.0.0 | — | — |
spryker/quote-request Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.