The stable version, clear license, and focused package layout make adoption straightforward. The repository is backed by an organization and matches the package, but it has no recent commit activity or security policy.
64%
Total Score
75
100
86
75
Only three releases have been published, with none in the last three years and a median interval of about 281 days. This lowers confidence in ongoing registry maintenance, although the repository was pushed more recently.
There were zero commits and zero active maintainers in the last three months. That is direct evidence of limited current development activity and increases abandonment risk.
The repository uses Composer, but no security scanning tooling is present. This is a maintenance and transparency gap, though not severe enough to make the release unfit by itself.
The repository has no security policy. For a small administrative module this is a transparency gap, but it is partially offset by the package's clear ownership and limited scope.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
oxid-esales/oxideshop-ce Version 6.1 - 6.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.