The MIT license and small Composer dependency set make the package straightforward to inspect and integrate. However, it has had no release or commit activity since July 2018, with no tests or security scanning, so long-term compatibility and maintenance are serious concerns.
38%
Total Score
50
100
75
50
Only two releases were published, with the latest in July 2018 and none in the last eight years, indicating prolonged abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the stale release history and offering no evidence of current maintenance.
Composer is used for the build, but no security scanning tools are configured, leaving a modest repository hygiene gap.
The linked repository is not archived, but its last push was in July 2018; availability does not compensate for the lack of recent activity.
The repository has no security policy, reducing transparency for vulnerability reporting in a package that has otherwise seen no recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
avored/ecommerce Version 2.* | — | — |
avored/module-installer Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.