Healthy and suitable to use. It has frequent releases, active work from seven contributors, strong package and repository documentation, and no deprecation or archive concerns. The main caveats are the absent security policy and undeclared workflow token permissions.
88%
Total Score
100
50
94
80
Twenty runtime dependencies create a meaningful upgrade and compatibility surface for this security-related module, though the profile is coherent with a feature-rich Spryker UI component.
Composer build tooling is present, but no security-scanning tooling was detected. The absence of automated security scanning is a transparency and assurance gap for a security-related module.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a genuine transparency gap for a module handling authentication-related UI.
The one workflow has no top-level token permissions declaration. Although no write permissions were observed, explicitly restricting workflow permissions would provide stronger CI supply-chain hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10953 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. spryker/security-gui is vulnerable to Auth Bypass in versions 1.10.0 - 2.0.2. | 1.10.0 - 2.0.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/gui Version ^5.1.0 | — | — |
spryker/log Version ^3.17.0 | — | — |
spryker/http Version ^1.16.0 | — | — |
spryker/user Version ^3.32.0 | — | — |
spryker/oauth Version ^2.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.