The module has a clear README, tests, release notes, and a matching license. Its organization-backed repository is active, but sparse releases and unpinned workflow actions merit attention.
76%
Total Score
100
90
50
Six releases since 2017 and one release in the last 12 months indicate a sparse cadence, but the current release and recent repository activity provide some compensation.
The repository has no security policy, leaving vulnerability reporting and handling less transparent for a maintained commerce module.
All 19 analyzed action references are unpinned, and the audit found high-confidence template-injection findings in php.yml. No untrusted checkout or script-injection trigger was found, so this is workflow hygiene risk rather than a severe dependency-health verdict.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.