The package has a clear license, matching source repository, and simple dependency footprint. Its small user base and lack of security tooling make long-term support less reassuring.
58%
Total Score
0
100
67
50
The latest release was over 3 years ago, with no releases in the last 12 months. This is the strongest maintenance concern, although the package has a history of 13 releases.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and increasing abandonment risk.
The repository has 6 stars, 4 forks, and 2 watchers. This is limited adoption evidence, though popularity is supporting evidence rather than a health verdict.
Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate, while the missing security checks modestly reduce confidence.
The repository has no security policy, reducing transparency about how users should report vulnerabilities. This is a meaningful hygiene gap for an extension handling store and invoicing integrations.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.