Tests, changelog, and release notes make the package easier to maintain and adopt. The repository lacks a security policy and has two of four workflow references unpinned, but the workflow audit found no active high-risk patterns.
88%
Total Score
100
94
50
The repository uses Composer build tooling, but no security-scanning tool was detected. That is a modest transparency and hygiene gap, not evidence of abandonment by itself.
No repository security policy was found. This reduces transparency for reporting and handling vulnerabilities, though active maintenance and organization backing partly offset the concern.
All workflows were analyzed successfully and the audit found no reported security findings or untrusted checkouts. Two of four action references are unpinned, which is a minor reproducibility concern rather than a severe workflow risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10899 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. spryker/session is vulnerable to SQL Injection in versions 0.20.0 - 4.19.1. | 0.20.0 - 4.19.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/redis Version ^2.0.0 | — | — |
spryker/config Version ^3.0.0 | — | — |
spryker/kernel Version ^3.52.0 | — | — |
spryker/symfony Version ^3.5.0 | — | — |
spryker/monitoring Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.