Clear documentation, tests, and licensing support adoption. Unpinned workflow actions and the missing security policy leave moderate hygiene risk.
68%
Total Score
83
100
81
50
The package is only 44 days old, with four releases clustered on its first day. This shows initial activity but provides little evidence of long-term maintenance.
All 10 recent commits came from one contributor, creating a concentrated maintenance risk. Organization backing partly offsets handoff risk but does not provide evidence of a second active maintainer.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity alone does not outweigh the observed activity and organization backing.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a package handling commerce domain data.
Version 0.4.0 is not a stable major release, although it is not marked as a prerelease and recent releases have not used prerelease versions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.0 | — | — |
liberusoftware/module-manager Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.