Healthy and suitable to depend on. It has a long release history, a current stable release, recent activity from five contributors, and strong repository and package structure; security-policy and workflow-permission gaps warrant routine review.
86%
Total Score
100
100
89
80
The repository has zero stars and two forks, indicating limited public popularity. The low visibility is only supporting evidence and is outweighed by the organization's ownership, release history, and active contributors.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency and assurance gap, not evidence of abandonment.
The repository has no security policy. This reduces vulnerability-reporting transparency, although the package's active organization-backed maintenance provides some compensation.
The sole workflow lacks top-level token permissions declarations. No workflow requests top-level write access, but explicitly constrained permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.0.0 | — | — |
spryker/queue Version ^1.0.0 | — | — |
spryker/store Version ^1.19.0 | — | — |
spryker/kernel Version ^3.49.0 | — | — |
spryker/search Version ^8.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.