Package Health

spryker/sales-oms

Testing and release notes are present, with a clear package-to-repository match. Two of four workflow actions are unpinned; the project also lacks a security policy and automated security scanning.

Latest 0.1.5PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has six releases since June 2020, with one release in the last 12 months and the latest published in November 2025. This indicates ongoing maintenance, but the relatively slow cadence is a modest maturity concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning reduces supply-chain maintenance assurance without making the release unfit to use.

Security policycaution

The repository has no security policy. That leaves vulnerability reporting and response expectations unclear, which is a transparency gap for a maintained package.

Version stabilitycaution

Version 0.1.5 is not a prerelease, but the package remains below major version 1, so its API maturity is less established than a stable-major release.

Workflow auditcaution

The single workflow was fully analyzed with no injection or high-severity findings, and it has no top-level write permissions. However, two of four action references are unpinned, a minor reproducibility concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/oms
Version ^11.21.0
spryker/sales
Version ^11.0.0
spryker/kernel
Version ^3.33.0
spryker/symfony
Version ^3.0.0
spryker/transfer
Version ^3.25.0

Weekly Downloads

Info

Last Published
10 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform