The source project remains active, organization-backed, and has multiple recent contributors. However, this exact release is explicitly marked invalid, and the registry has had no newer release for about seven years.
30%
Total Score
100
25
The release includes a README, changelog, and release notes, but those notes explicitly warn that version 1.0.0 is invalid and should be skipped. That warning is a severe release-fitness concern despite the otherwise adequate documentation.
This package has only one release, published about seven years ago, with no releases in the last 12 months. The linked repository is active, but that activity has not produced a newer registry release.
The manifest declares a proprietary license and a LICENSE file is present in both the package and repository, so this is licensed rather than an unlicensed-release gap. The proprietary terms may still limit adoption for projects requiring an open-source license.
Version 1.0.0 is a stable, non-prerelease version, but stability labeling does not offset the release notes' explicit warning that this particular release is invalid.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, which is a minor reproducibility weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.