spryker/service-point 1.3.0 appears healthy and suitable for dependency use. It is a mature package with 19 releases over more than three years, a stable major version, a non-deprecated registry status, a current unarchived repository, comprehensive source and test structure, and recent activity from six maintainers. The main concerns are repository security hygiene: no security policy was found and the CI workflow does not declare top-level token permissions. Release frequency has also slowed to one release in the last 12 months, but ongoing commits, broad contributor activity, and current repository activity substantially reduce abandonment risk.
86%
Total Score
100
100
94
80
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning tooling is a hygiene gap, though other repository and workflow signals remain healthy.
No SECURITY.md or equivalent security policy was found in the repository, leaving vulnerability-reporting and response expectations less transparent.
The only CI workflow lacks top-level token permissions, so its effective permissions are not explicitly minimized in the repository configuration. No top-level write permissions were observed, limiting the severity of this hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/gui Version ^4.0.0 || ^5.0.0 | — | — |
spryker/store Version ^1.12.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/country Version ^4.1.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.