Organization backing, a clear license, and practical usage documentation support adoption. Recent commit activity is absent, the repository is lightly used, and workflow actions are all unpinned, so maintenance and build-integrity risks remain.
68%
Total Score
75
100
83
83
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance slowdown despite recent repository activity and merged pull requests.
The repository name does not match the package name and its README does not mention the package, creating some uncertainty about package-to-repository alignment; the organization context partly reduces that concern.
The repository has one star and no forks, indicating limited public adoption; this is supporting caution rather than evidence of abandonment by itself.
The project uses Make and Composer, but no security scanning tools were detected; the organization security policy partly compensates for this hygiene gap.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, all three action references are unpinned, leaving the build exposed to mutable action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ^6.5.8 | — | — |
gally/gally-php-sdk Version 2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.