Recent releases, four active contributors, release notes, documentation, and tests show substantial ongoing work. Pin the named replacement package rather than starting a new dependency on this one.
42%
Total Score
100
79
67
Packagist marks the entire package as abandoned and names nexi-checkout/shopware6-checkout as its replacement. This is a major adoption risk despite the recent release and active repository.
The project uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning automation is a modest hygiene concern for a payment integration.
No repository security policy was found. This reduces transparency for reporting vulnerabilities in a package that handles payment integration, though it is not evidence of abandonment by itself.
The single workflow was fully analyzed with no untrusted checkout or script-injection trigger, but both action references are unpinned and high-confidence template-injection findings were reported. These are workflow hygiene and supply-chain concerns, not independently severe enough to determine the score.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
shopware/storefront Version ~6.6.0 || ~6.7.0 | — | — |
nexi-checkout/php-payment-sdk Version ~0.16 | — | — |
giggsey/libphonenumber-for-php-lite Version ^8.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.