CoreShop - Currency Bundle
67%
Total Score
75
100
79
75
The manifest declares a proprietary license, but LICENSE.md is present in the artifact and repository, so the release is licensed rather than missing licensing information. The proprietary terms may still restrict use compared with permissive alternatives.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent registry release and repository push provide some compensating evidence.
The repository name does not match the package name, and its README does not mention this package. That creates some uncertainty about whether the linked repository is the authoritative source, though the repository is an evidently related CurrencyBundle project.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a hygiene weakness rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This modestly reduces transparency for a package used in commerce software.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/intl Version ^6.4.14 || ^7.2 | — | — |
pimcore/pimcore Version ^2026.2 | — | — |
coreshop/currency Version ^2026.1 | — | — |
coreshop/resource-bundle Version ^2026.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.