Documentation is practical, and the organization-owned repository is correctly linked. There is no security policy or automated security scanning, so adoption needs extra maintenance oversight.
55%
Total Score
67
86
83
The latest registry release was in June 2020, with no releases in the last 12 months despite the package being over six years old. This substantially raises staleness and compatibility risk.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
Only one commit was recorded in the last three months, from one active maintainer. That is limited recent activity and leaves little evidence of sustained maintenance capacity.
Composer is used for builds, but no security-scanning tools are present. For a payment integration, that leaves a meaningful maintenance and review gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
esas/cmsgate-epos-lib Version ~v1.10.0 | — | — |
esas/cmsgate-woocommerce-lib Version ~v1.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.