The package has a clear README, repository tests, regular releases, and no install-time scripts. The repository lacks security scanning and a security policy, so maintenance transparency is limited.
65%
Total Score
50
100
88
88
The manifest declares LGPL-3.0-or-later, while the artifact license file is recognized as LGPL-2.1. The package is licensed, but the mismatch creates an avoidable compliance question.
The repository recorded zero commits and zero active maintainers in the last 3 months. The same-day release and push provide some compensating evidence, but the recent activity measurement still indicates a thin maintenance signal.
The repository uses Composer for builds, but no security scanning tools were detected. The missing scanning reduces automated maintenance assurance without making the package unfit.
No security policy was found in the repository. This is a transparency and reporting gap, though it is less serious for a small extension with no other security warning provided.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aimeos/aimeos-core Version 2026.10.* | — | — |
aimeos/ai-controller-frontend Version 2026.10.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.