Laravel package for making LWA- / RDT-authorized requests to Amazon Selling Partner API (SP-API)
72%
Total Score
63
100
89
90
Only one registry publisher account is listed. That is a mild resilience concern, though the account is an organization-named development team and the repository provides corresponding project backing.
The repository is owned by the glue-systems user account rather than an organization account. This does not establish strong organizational backing, but the repository owner and package naming are consistent with the package.
No commits and no active maintainers were recorded during the last 3 months, which is a meaningful maintenance warning. This is partly offset by the recent repository push, releases, and two merged pull requests, so it indicates caution rather than severe abandonment.
The repository has only 3 stars, 0 forks, and 3 watchers. Low adoption does not make the package unsafe by itself, but it provides little independent evidence of maturity or community support.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a security-process gap, not evidence that the release is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^12.0 || ^13.0 | — | — |
glue-systems/sp-api-open-api Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.