Healthy and suitable to depend on. It has current releases, active contributions from six maintainers, tests, and a matching source repository; the main gaps are missing security-policy documentation and unspecified workflow token permissions.
86%
Total Score
100
93
80
Composer build tooling is present, but no security-scanning tools were detected. This limits evidence of automated vulnerability checks and modestly lowers transparency.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. This is a modest transparency gap, not evidence that the package is unsafe.
The repository's CI workflow does not declare top-level token permissions. Although no write permissions were detected, explicitly restricting the token would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.0.0 | — | — |
spryker/twig Version ^3.0.0 | — | — |
spryker/money Version ^2.8.0 | — | — |
spryker/store Version ^1.19.0 | — | — |
spryker/kernel Version ^3.72.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.