Usable with caveats: the package is clearly documented, tested, licensed, and backed by an organization, but maintenance appears stalled. It has had no release or repository commit activity in over a year, and the repository lacks security scanning and a security policy.
62%
Total Score
50
50
83
80
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This is the main abandonment concern.
Eight runtime dependencies are declared, including several framework and infrastructure components, creating meaningful compatibility and maintenance surface. The dependency set is coherent with the package's Spryker debugging functionality but is not minimal.
Only two releases exist, with the latest published over a year ago and no releases in the last 12 months. This materially weakens confidence in ongoing maintenance for a package with runtime dependencies.
The repository has one star, no forks, and no watchers, showing little community visibility. Popularity is only supporting evidence, so this does not outweigh the stronger maintenance signals by itself.
Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate while security-process transparency is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/propel Version ^3.0 | — | — |
spryker/console Version ^4.0 | — | — |
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
spryker/rabbit-mq Version ^2.0 | — | — |
symfony/var-dumper Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.