It includes a README, tests, MIT licensing, and release notes, while the repository remains unarchived. The missing security policy and two unpinned workflow actions reduce transparency and build reproducibility.
52%
Total Score
50
83
50
Only two releases were published, with the latest on May 30, 2022 and none in the last 12 months. That long pause is a meaningful maintenance concern despite the documented 0.2.5 release notes.
The repository had zero commits and zero active maintainers in the three months measured. Together with the old latest release, this suggests limited recent maintenance capacity.
The project uses Make and Composer, but no security-scanning tools were detected. This is a transparency and maintenance gap, though it is less severe because the package has tests and a documented build structure.
No repository security policy was found. That makes vulnerability reporting and project response expectations less clear for consumers.
The single workflow was fully analyzed, uses read-only permissions, and has no audit findings, but both action references are unpinned. Pinning would improve build reproducibility and resistance to action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/kernel Version ^3.54.0 | — | — |
php-vcr/php-vcr Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.