Healthy and suitable to use, with a small maintenance risk. It has a long release history, a current stable release, active organizational backing, and a repository that is not archived; recent work is concentrated in one contributor and the repository lacks security-policy and explicit workflow permissions.
78%
Total Score
88
100
94
75
All recent commits came from one contributor, giving the project a concentrated short-term maintenance base. Organizational ownership provides some handoff capacity, but no second active contributor is shown.
The repository uses Composer build tooling, but no security-scanning tool was detected. This is a transparency and assurance gap, though it is not by itself evidence that the package is unsafe or abandoned.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's active organizational backing partly reduces the maintenance concern.
Neither workflow declares top-level token permissions. No workflow requests top-level write access, but the absence of explicit permissions leaves the repository's CI authorization less transparent than it could be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.