Usable with caveats: this is a newly published package with no demonstrated maintenance history, and its linked repository does not clearly identify the package. The small artifact lacks tests, a changelog, and a security policy, so verify ownership and support before relying on it in production.
58%
Total Score
50
69
75
A readable installation guide is present, but neither the artifact nor repository contains tests or a changelog. For an integration module handling catalogue, orders, webhooks, and API tokens, those omissions reduce transparency and confidence in maintenance.
The package is brand new, with one release published today and no release history to demonstrate sustained maintenance or compatibility practice. Its age is too short to establish abandonment, so this is a caution rather than a danger.
The repository has no commits in the last three months and no active maintainers in that period. Because the package was released today, this may reflect a new project rather than confirmed abandonment, but it provides no demonstrated ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. This creates a concrete risk that the linked source repository is not actually the source for this release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any adoption signal adds to the uncertainty for a newly released package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.