Usable with caveats: the release is licensed, stable, clearly backed by a matching repository, and has no deprecation or dangerous workflow findings. However, all five releases appeared within minutes and the repository has had no commits for about 11 months, with no repository tests or security policy.
62%
Total Score
0
75
67
The repository recorded zero commits and zero active maintainers in the last three months, a significant maintenance and abandonment concern for a framework tied to evolving WooCommerce versions.
The artifact includes a README and documentation, which is important for a testing framework. It contains no tests or changelog, and the repository also reports no tests; absent tests are a meaningful confidence gap for a package whose purpose is testing.
The package has five releases in the last year, but all were published within minutes of one another, showing an initial publication burst rather than an established release cadence.
The repository uses Composer, but it reports no security scanning tools. That weakens security hygiene somewhat, although it is not evidence that the package is unsafe or unmaintained by itself.
The linked repository is not archived, but its last push was about 11 months ago, which is consistent with the separate evidence of stalled recent maintenance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.