The package has clear ownership, MIT licensing, a focused dependency set, and a clean workflow audit. Its repository was pushed recently, but the release and commit signals show an uneven maintenance cadence, with no commits in the last three months.
68%
Total Score
67
100
88
75
The package has 11 releases over roughly 35 months, but none in the last 12 months and the latest registry release was about 16 months ago. This weakens confidence in ongoing release maintenance.
The repository recorded zero commits and zero active maintainers during the last 3 months. Although a separate signal shows a push about 2 months ago, the measured commit activity still indicates a thin recent maintenance cadence.
There were no new or closed issues or pull requests in the last month, while four pull requests remain open. This is a modest sign of limited visible project activity rather than evidence of abandonment by itself.
The repository uses Composer, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a package handling storefront access control.
The repository has no security policy. For an access-control plugin, the missing reporting guidance is a genuine but limited transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0||~6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.