Tests, a changelog, a clear license, and a security contact make the project easier to maintain and adopt. Its large runtime dependency set adds integration complexity.
68%
Total Score
83
50
86
100
The package declares 30 runtime dependencies, including Shopware, Symfony, and several HEPTAconnect components. This is understandable for an integration bridge but increases upgrade and compatibility complexity.
The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance. A release was published recently, so this is a concern rather than proof of abandonment.
The repository uses Make and Composer, but no security scanning tools were detected. That leaves a meaningful verification gap for a package with substantial runtime dependencies.
Version 0.9.8.3 is not a stable-major release, so its public compatibility expectations may still be less settled than a 1.x package. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 | — | — |
nyholm/psr7 Version ^1.2 | — | — |
ramsey/uuid Version ^3.5 || ^4 | — | — |
symfony/lock Version >=5.2 | — | — |
doctrine/dbal Version >=2.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.