This is a healthy, mature release with a long release history, frequent recent releases, stable versioning, active organizational backing, and a repository that is current, correctly associated with the package, and supported by tests, documentation, a changelog, and reproducible Composer tooling. The main concerns are transparency and operational hygiene: the repository has 91 open issues with no issues closed in the last month, lacks a security policy and automated security scanning, and its four workflows do not declare top-level token permissions. These issues warrant review before adoption but do not outweigh the package's sustained maintenance and strong project structure.
88%
Total Score
90
100
94
80
There are 91 open issues and no issues closed in the last month, although two pull requests were opened and two merged during that period. The pull-request activity is encouraging, but the unresolved issue backlog is a maintenance-hygiene concern.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a supply-chain hygiene gap, though it is not evidence of a malicious package.
The repository has no security policy, leaving vulnerability-reporting and coordinated-disclosure guidance unspecified. This is a transparency gap for a package that integrates with Magento and external services.
All four workflows lack top-level GitHub Actions permissions declarations. Although none declares top-level write permissions, explicitly setting least-privilege permissions would provide stronger workflow hardening and transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
myparcelnl/sdk Version 11.0.0-beta.15@beta | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
magento/framework Version >=101.0.8 <102 || >=102.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.