Plugin to display the ean on the detail page
38%
Total Score
unhealthy
Risky: no release or commit activity for nearly six years, with a proprietary license and an unrelated-looking repository.
The manifest declares a proprietary license, with no detected license text or license file. That leaves usage and redistribution rights unclear for a package presented as open source.
The last release was nearly six years ago, with no releases in the past 12 months. Four releases over the package's lifetime show some history, but do not offset the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's long release silence and elevated abandonment risk.
The repository name does not match the package name and its README does not mention the package, so the linked source may not clearly document or belong to this release.
Composer is used as a build tool, which is appropriate for this package, but no security-scanning tools were detected. This is a modest transparency and maintenance gap, not evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.