The repository is not archived, and the package includes a README, changelog, and release notes for this version. Its registry status and release history indicate that this release should not be adopted as a new dependency.
18%
Total Score
75
63
83
Packagist marks the entire package as abandoned, with no replacement named. Package-level abandonment is a severe dependency risk even though the repository still exists.
The latest registry release was about seven years ago, with zero releases in the last 12 months. This strongly indicates the published dependency is no longer actively maintained.
The repository had no commits and no active maintainers in the last three months. Although the repository was pushed in October 2024, current maintenance activity is absent.
Composer build tooling is present, but no security scanning tooling was detected. This is a hygiene weakness, not the primary reason to reject the release.
The repository has no security policy. That limits vulnerability-reporting transparency, although the package's abandonment and stale release history are more decisive.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/stock Version ^4.0.0 || ^5.0.0 || ^7.0.0 | — | — |
spryker/kernel Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.