The package has a clear README, a matching MIT license, and a small runtime dependency surface. Its young project history, two recent commits, and single active contributor leave limited evidence of durable maintenance.
67%
Total Score
50
100
88
50
The registry namespace and repository owner are the same individual account, which provides some identity consistency but does not demonstrate organization-level backing or a broader maintenance team.
The package is only 110 days old with eight releases, including eight in the last 12 months; this shows active early development but not yet a long maintenance record. Releases are closely clustered, with a median interval of about 16 hours.
One contributor made all two commits in the last three months, leaving maintenance concentrated in a single person with no demonstrated handoff capacity.
Only two commits were recorded in the last three months. The recent push is encouraging, but this is limited observable maintenance activity for a package intended for production integration.
Composer is used for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version >=6.7 <6.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.