The package has a long release history, recent publication, and clear organizational ownership. Missing security scanning and a security policy leave fewer safeguards around future changes, while repository activity has recently paused.
67%
Total Score
75
81
75
The manifest declares a proprietary license and the artifact contains LICENSE.md, with a corresponding repository license file. The release is therefore licensed, though its terms may restrict use compared with an open-source license.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Against the otherwise long release history, this indicates a recent maintenance pause and lowers confidence in ongoing responsiveness.
The repository name does not exactly match the package name and its README does not mention the package. Because the repository is otherwise under the matching CoreShop organization, this is a provenance concern but not conclusive evidence of misattribution.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful supply-chain hygiene gap for future changes.
No security policy was found in the repository. This reduces transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimcore/pimcore Version ^2026.2 | — | — |
coreshop/registry Version ^2026.1 | — | — |
coreshop/shipping Version ^2026.1 | — | — |
coreshop/rule-bundle Version ^2026.1 | — | — |
coreshop/money-bundle Version ^2026.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.