Package Health

spryker/store-storage

This release appears healthy and suitable to depend on: it is a stable 1.5.0 release from a package with 11 releases, 6 releases in the last 12 months, and a latest release published very recently. The linked Spryker organization repository is active, unarchived, clearly matches the package, has tests and changelog coverage, and shows 8 commits from 8 active maintainers over the last 3 months, indicating strong maintenance capacity and low bus-factor risk. The main reservations are the absence of a repository security policy, no detected security-scanning tooling, and no top-level GitHub Actions token-permission declaration; these are repository-hygiene gaps rather than evidence of abandonment or an unfit dependency.

Latest 1.5.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap, though it is partly offset by the repository's active CI and does not by itself indicate abandonment.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency, although it is a moderate hygiene concern rather than evidence that the package is unsafe or abandoned.

Token permissionscaution

The one analyzed workflow lacks a top-level token-permissions declaration. Although no top-level write permissions were detected, explicitly declaring least-privilege permissions would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spryker/store
Version ^1.37.0
spryker/kernel
Version ^3.30.0
spryker/locale
Version ^4.0.0
spryker/country
Version ^4.0.0
spryker/storage
Version ^3.4.0

Weekly Downloads

Info

Last Published
14 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform