Tests, a clear README, and two recent stable releases support practical adoption. The workflow uses read-only permissions, but all three actions are unpinned.
62%
Total Score
50
100
88
75
The manifest declares a proprietary license, while the artifact and repository contain an MIT license file. That inconsistency creates legal ambiguity even though a license is present.
The repository is owned by a personal GitHub account rather than an organization, so the concentrated contributor activity is not visibly supported by organizational handoff capacity.
One contributor made all four commits in the last 3 months, leaving maintenance highly concentrated and increasing handoff risk.
The repository received four commits in the last 3 months, showing some ongoing maintenance, but activity is limited in volume.
The project uses Make and Composer build tooling, but no security-scanning tool was detected. The missing scanning is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
shopware/fixture-bundle Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.