Healthy and suitable to depend on. The organization-backed repository is active, has five recent contributors, tests, and a stable release history; the main caveats are no security policy and unspecified workflow token permissions.
82%
Total Score
100
100
94
80
The repository uses Composer build tooling, but no security-scanning tools were detected. The build setup is present, though security automation is a transparency gap.
No repository security policy was found. This does not show unsafe code, but it leaves vulnerability-reporting expectations and response procedures undocumented.
The only workflow has no top-level token permissions declaration. Although no write permissions were detected, explicitly restricting permissions would provide stronger workflow-hardening evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.27.0 | — | — |
spryker/serializer-extension Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.