Documentation, tests, and release notes are present, and the repository is not archived. A single maintainer and no security policy or scanning leave limited evidence for long-term support.
68%
Total Score
50
100
88
83
The registry namespace and repository are owned by the same individual account, providing consistent ownership evidence. Individual ownership also means the project has a narrow visible backing base.
This is the first release, published 0 days ago, so there is no release cadence or track record to assess yet. That limits confidence but does not indicate abandonment in a newly launched package.
There were 0 commits and 0 active maintainers in the last 3 months, but the package and repository are both only 0 days old. The absence is therefore an unproven maintenance history rather than evidence of a collapsed project.
Composer build tooling is present, but no security scanning tool was detected. That leaves a modest transparency and maintenance-hygiene gap for a package intended for production commerce systems.
The repository has no security policy. This makes vulnerability reporting and response expectations unclear, which is a real but limited adoption concern for a new integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.3.0 | — | — |
justinholtweb/craft-carrier Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.