The repository is active and includes tests, a changelog, and a clear README. One person handles all recent commits, and all three workflow actions are unpinned, leaving meaningful maintenance and build-integrity concerns.
68%
Total Score
75
88
50
The package runs post-install and post-update Composer scripts, which add installation-time behavior beyond shipping stub files and warrant some caution.
The package is only 48 days old with two releases, so its maintenance and release track record are still limited despite the recent activity.
One contributor made all six recent commits, leaving the project dependent on a single individual's continued availability.
The repository uses Composer build tooling, but no security scanning tool was detected; for a small generated-stub project this is a modest transparency gap.
No repository security policy was found, reducing clarity about how vulnerabilities should be reported, though this is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mralaminahamed/fluent-cart-stubs Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.