Testing and release notes are present, with a clear package-to-repository match. Two of four workflow actions are unpinned; the project also lacks a security policy and automated security scanning.
78%
Total Score
100
79
75
The package has six releases since June 2020, with one release in the last 12 months and the latest published in November 2025. This indicates ongoing maintenance, but the relatively slow cadence is a modest maturity concern.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning reduces supply-chain maintenance assurance without making the release unfit to use.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear, which is a transparency gap for a maintained package.
Version 0.1.5 is not a prerelease, but the package remains below major version 1, so its API maturity is less established than a stable-major release.
The single workflow was fully analyzed with no injection or high-severity findings, and it has no top-level write permissions. However, two of four action references are unpinned, a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/oms Version ^11.21.0 | — | — |
spryker/sales Version ^11.0.0 | — | — |
spryker/kernel Version ^3.33.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.25.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.