The package includes tests, a changelog, and a small runtime dependency set. The linked repository does not identify this package, and recent repository activity is absent despite the latest release; the organization backing provides some reassurance, but security documentation is missing.
58%
Total Score
67
100
78
75
The package has five releases over about two years and eight months, but only one in the last 12 months. The latest release is recent enough to show some maintenance, though the overall cadence is limited.
The repository has no commits and no active maintainers in the last three months. The matching recent release partly offsets this, but the lack of ongoing activity raises maintenance risk.
There are no open issues or pull requests and no activity in the last month. This is neutral when the project may simply be quiet, but it offers no evidence of active community maintenance.
The repository name does not match the package name and its README does not mention the package. This creates a meaningful risk that the linked source is not the actual package repository.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures provide little external confirmation of project adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.7.0 | — | — |
shopware/storefront Version ~6.7.0 | — | — |
promphp/prometheus_client_php Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.