The MIT license, small dependency set, and organization-owned repository provide useful transparency. A changelog is present, but there is no README and no established release or commit history yet.
60%
Total Score
75
100
83
75
A changelog is present, but the published artifact has no README. For a library exposing APIs and integration components, that reduces consumer-facing transparency.
This is the package's first release, published less than an hour before collection, so there is no demonstrated release cadence or long-term maintenance record.
The repository recorded zero commits and zero active maintainers over the past three months. Because this is a newly published package and was pushed immediately before collection, the result is more a lack of history than evidence of abandonment.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities in a package that exposes reseller APIs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dashed/dashed-core Version ^4.71 | — | — |
dashed/dashed-ecommerce-core Version * | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.