The MIT license, focused dependency set, and matching organization repository improve transparency. Documentation is present, but the project has no security policy or automated security scanning.
68%
Total Score
100
79
50
The package is only 122 days old and has 35 releases, with a median interval of about 4 hours 31 minutes. This shows active iteration but also limited maturity and an unusually rapid release cadence.
Composer is used as the build tool, but no security scanning tools were detected. For a package handling inventory and checkout-related operations, this is a meaningful repository hygiene gap.
No repository security policy was found. This reduces transparency about how vulnerabilities should be reported, although it does not by itself show that the package is unsafe.
The assessed version is v0.1.34, so the package has not reached a stable major release. It is not marked as a prerelease, which provides some compensation, but API-change risk remains.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aiarmada/commerce-support Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.