Clear licensing, release notes, and organization backing improve transparency. The small repository lacks security scanning and a security policy, while activity has stopped for about 18 months.
58%
Total Score
67
100
88
75
The package has only two releases, with the latest published about 18 months ago and no releases in the past 12 months. This is a meaningful maintenance concern for a package that reached a stable major version.
There were no commits and no active maintainers during the past three months, consistent with the long release gap. This lowers confidence that defects or compatibility changes will be addressed promptly.
The repository has one open issue and no issue or pull-request activity in the past month. This is a modest sign of limited ongoing maintenance rather than evidence of abandonment on its own.
Composer build tooling is present, but no security-scanning tool was detected. That weakens repository hygiene and gives less evidence of routine security maintenance.
No security policy was found in the repository. For a package that validates VAT data and participates in checkout behavior, this is a transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.