45%
Total Score
38
50
67
83
Only two releases were published, both in January 2020, with no release in over six years. This is strong evidence of abandonment unless the package is intentionally frozen.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and materially increasing abandonment risk.
The package has three runtime dependencies, including Symfony and another ShipStation package, which is a manageable dependency surface but leaves consumers exposed to the health of those dependencies.
Only one registry publishing account is present. Because the project is user-owned rather than organization-backed, this indicates a thin maintainer base and limited continuity.
The published artifact has no README, while the repository also has no tests or changelog. Missing tests and changelog are not expected in the artifact, but the absence of a consumer-facing README is a real transparency gap for a library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zack6849/ship-station Version ^1.2 | — | — |
symfony/framework-bundle Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.