Four contributors made 12 commits in three months, and the package includes tests, a changelog, and release notes. It lacks a security policy and has little community adoption, so ongoing support depends mainly on the owning organization.
70%
Total Score
100
100
88
67
The linked repository name does not match the package name and its README does not mention the package, leaving uncertainty about whether the repository is the intended source rather than a related or reused project repository.
The repository has only 4 stars and 4 forks, indicating limited public adoption. This is supporting evidence rather than a health verdict, and the active organization-backed maintenance offsets much of the concern.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a payment integration. The active organization-backed project and recent release activity partly compensate but do not remove this gap.
The only workflow was fully analyzed and has no untrusted checkout, script injection, or broad top-level write permissions. However, it has high-confidence template-injection findings and all 2 action references are unpinned; the absence of a dangerous trigger limits the immediate severity, but this remains a meaningful release-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
shopware/storefront Version ~6.6.0 || ~6.7.0 | — | — |
nexi-checkout/php-payment-sdk Version ~0.16 | — | — |
giggsey/libphonenumber-for-php-lite Version ^8.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.