Clear packaging, tests, release notes, and organization-backed maintenance make this easy to evaluate. Two of four workflow actions are unpinned and no security policy is published, so repository hygiene deserves attention.
76%
Total Score
100
88
75
The package has 34 releases over more than eight years, but none in the last 12 months despite a 26-day median historical interval. This indicates a meaningful registry-cadence slowdown, partly offset by recent repository activity.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a modest repository-hygiene gap rather than evidence of unsafe code.
The repository has no published security policy. That weakens vulnerability-reporting transparency, although active organization-backed maintenance partly offsets the concern.
The single workflow was fully analyzed with no injection, untrusted-checkout, or high-confidence audit findings. However, two of four action references are unpinned, leaving avoidable supply-chain hygiene risk; the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/cart Version ^5.1.0 || ^7.0.0 | — | — |
spryker/quote Version ^2.8.0 | — | — |
spryker/store Version ^1.0.0 | — | — |
spryker/kernel Version ^3.33.0 | — | — |
spryker/customer Version ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.