Workflow references are only partly pinned, and the repository has no published security policy. The package includes release notes, a README, and a changelog, while its organization ownership supports continuity.
80%
Total Score
100
88
67
The package has existed for about 7 years with five releases and one release in the last 12 months; the latest release is recent, but the overall cadence is modest.
The repository uses Composer build tooling, but no security-scanning tools were detected, leaving a modest verification gap.
No security policy was found in the repository, which weakens disclosure transparency for a package exposing REST API functionality.
The single workflow was fully analyzed with no audit findings or untrusted execution sinks, but 2 of 4 action references are unpinned; the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.30.0 | — | — |
spryker/symfony Version ^3.0.0 | — | — |
spryker/transfer Version ^3.42.0 | — | — |
spryker/container Version ^1.10.0 | — | — |
spryker/url-storage Version ^1.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.