The repository is recently active and organization-backed, with a focused dependency set and no install-time scripts. Documentation is present in the source tree, but the project lacks a security policy and its version history is unusually rapid for a young package.
70%
Total Score
100
100
79
75
The package is only 176 days old but has 36 releases, with a median interval of about 5 hours, showing active development but an unusually fast cadence that can increase upgrade churn.
Composer is used as the build tool, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap rather than evidence of abandonment.
The linked repository has no security policy, leaving vulnerability-reporting expectations and response guidance unspecified.
The assessed release is v1.1.0 while the observed latest version is v0.1.34, and the package is not on a stable major line; this inconsistency lowers confidence in version maturity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aiarmada/commerce-support Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.