Documentation, tests, and release notes are solid, and the repository remains active rather than archived. The lack of a security policy and fully unpinned workflow actions leave avoidable maintenance and build-integrity gaps.
62%
Total Score
75
100
88
75
The package has 9 releases over roughly three years, but none in the last 12 months despite a latest release more than a year ago. This indicates a meaningful slowdown, although the prior median interval of about 49 days shows an established release history.
There were 0 commits and 0 active maintainers in the last three months. That is a concrete maintenance warning, even though the repository is not archived and has a longer release history.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. The missing scanning layer is a modest transparency and maintenance gap.
No security policy was found in the repository. For a package used in deployment tooling, this makes vulnerability reporting and response expectations less clear.
The sole workflow was fully analyzed with no high-confidence audit findings or untrusted triggers, but both of its two action references are unpinned. The absence of a top-level permissions block is acceptable on its own, while fully unpinned actions leave a build-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.54.0 | — | — |
spryker/console Version ^4.10 | — | — |
spryker/propel-orm Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.