Strong test coverage and eight active contributors reduce maintenance risk. The workflow audit found no dangerous findings, though two of four actions are not pinned and no security policy is present.
88%
Total Score
100
50
94
75
The package declares 17 runtime and 11 development dependencies, a relatively broad profile for a framework module but one consistent with its documented multi-layer functionality.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a modest process gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package used across application layers.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Two of four action references are unpinned, a mild reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
spryker/config Version ^3.0.0 | — | — |
spryker/guzzle Version ^2.1.0 | — | — |
spryker/kernel Version ^3.52.0 | — | — |
spryker/locale Version ^3.0.0 || ^4.0.0 | — | — |
spryker/symfony Version ^3.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.