Tests, a clear MIT license, and no install-time scripts support predictable integration. The small dependency set and organization-backed repository add useful context, but limited security documentation and workflow pinning leave maintenance and build-integrity gaps.
57%
Total Score
75
100
81
67
The package contains tests, which is a positive for a PHP library, but it has no README for consumers; no repository README result was collected to compensate for that gap.
The package has had no release in more than three years, despite seven releases overall. This is a meaningful maintenance concern for a dependency, although the linked repository was pushed more recently.
There were no commits and no active maintainers in the last three months. Combined with the long release gap, this raises the risk that maintenance has slowed substantially.
The repository uses Composer and Make for build tasks, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap.
No security policy was found in the repository, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fond-of-oryx/gift-card-product-connector Version ^1.0.0 || ^2.0.0 | — | — |
fond-of-oryx/jellyfish-sales-order-extension Version ^1.0.0 || ^2.0.0 | — | — |
fond-of-oryx/product-cart-code-type-restriction Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.