Regular releases and a current repository support ongoing ownership. However, no commits were recorded in the last three months, and the manifest says proprietary while the license file says GPL; confirm the intended terms before adopting.
69%
Total Score
83
100
88
83
A license file exists in both the artifact and repository, but the manifest declares proprietary licensing while the repository license evidence indicates GPL. The conflicting terms create a real adoption and compliance concern.
No commits and no active maintainers were recorded in the last three months. This conflicts with the frequent release history and raises uncertainty about whether releases reflect active source maintenance.
Composer is used as the build tool, but no repository security-scanning tool was detected. This is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no published security policy. For a small component this is a limited disclosure gap, but it leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
coreshop/registry Version ^2026.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.