Five contributors made seven commits in the last three months, and the repository remains active under its owning organization. The missing security policy and two unpinned workflow actions leave avoidable maintenance and build-integrity gaps.
72%
Total Score
100
88
83
The package has 64 releases over roughly eight years, but none in the last 12 months; this is a meaningful release-cadence concern, partly offset by recent repository commits.
Composer build tooling is present, but no repository security-scanning tools were detected; this is a modest transparency gap rather than evidence of abandonment.
The repository has no documented security policy, leaving vulnerability-reporting expectations unclear for a production-oriented module.
The single workflow was fully audited with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, two of four action references are unpinned, creating a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/cart Version ^5.1.0 || ^7.0.0 | — | — |
spryker/event Version ^1.0.0 || ^2.0.0 | — | — |
spryker/store Version ^1.1.0 | — | — |
spryker/kernel Version ^3.30.0 | — | — |
spryker/product Version ^6.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.