Healthy and usable, with a concentrated maintenance risk. It has a long release history, a current stable release, active recent commits, and a matching organization-owned repository, but all recent work comes from one contributor and repository security documentation is limited.
78%
Total Score
88
100
94
67
All 15 commits in the last three months came from one contributor, creating a meaningful continuity risk. The organization-owned repository provides some ability to hand maintenance off, but no second recent contributor is shown.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces assurance but is not by itself evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented for a package that handles ecommerce functionality.
None of the three workflows declares top-level token permissions. Although no workflow is shown requesting top-level write access, the absence of explicit restrictions is a repository hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mlocati/vat-lib Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.