The package includes tests, a changelog, release notes, and a matching repository. Missing security policy and two unpinned workflow actions are modest hygiene concerns.
82%
Total Score
100
81
50
The package has 9 releases since October 2018, but none in the last 12 months; the latest registry release was over a year ago. Recent repository commits provide some maintenance evidence, partly offsetting the slow release cadence.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a modest transparency and assurance gap rather than evidence of abandonment.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
Version 0.2.3 is not a prerelease, and recent releases contain no prerelease versions. The pre-1.0 major version still signals a less mature compatibility commitment.
The single workflow was fully analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection paths. Two of four action references are unpinned, creating a limited reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/product Version ^5.0.0 || ^6.0.0 | — | — |
spryker/customer Version ^7.0.0 | — | — |
spryker/data-import Version ^1.0.0 | — | — |
spryker/company-user Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.