The MIT license, clear README, and small dependency surface make the library easy to adopt. No security policy or scanning is visible, and the inactive repository leaves future compatibility work to you.
58%
Total Score
50
100
80
50
Only two releases have been published since September 2022, with no release in the last 12 months; the latest was over two years ago. This indicates slow or stopped maintenance for a library tied to an evolving API.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the June 2024 release. The repository is not archived, but current maintenance activity is absent.
Composer is used for the build, which fits the package, but no security scanning tools are present. That weakens routine assurance without making the release unsuitable on its own.
The linked repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a transparency gap for a library that handles Shopify credentials and API access.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.