The package has a small dependency set and an explicit license. Its source repository shows no commits in three months and no security policy, while the repository does not clearly identify this package; pinning requires caution.
57%
Total Score
50
100
81
75
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern despite the recent push timestamp and regular registry releases.
The package includes a README, while the absence of tests and a changelog in the published artifact is normal packaging practice for this ecosystem. Repository-level tests and changelog evidence are not present, limiting project transparency somewhat.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository is the intended source rather than a related or reused repository.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning layer modestly reduces transparency and release assurance.
The repository has no published security policy. This leaves vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimcore/pimcore Version ^2026.2 | — | — |
coreshop/inventory Version ^2026.1 | — | — |
coreshop/resource-bundle Version ^2026.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.