This is a healthy, actively supported release from an organization-owned PrestaShop repository. The package is licensed, stable, non-deprecated, accurately tied to its source repository, includes tests and standard Composer tooling, and shows recent activity from two contributors with balanced commit share. The main concerns are the absence of a repository security policy and explicit top-level GitHub Actions token permissions, plus a relatively small release history and low repository popularity; these are hygiene and maturity limitations rather than evidence of abandonment. It appears reasonable to depend on, subject to normal review of its update and CI practices.
88%
Total Score
100
100
89
80
The package has existed for about 9 years with 9 releases, but only 1 release in the last 12 months; this is somewhat sparse, though recent repository activity provides some compensation.
The repository has only 4 stars and 32 forks, indicating limited visible popularity; this is a supporting caution rather than a decisive health concern because maintenance and organizational backing are present.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting guidance unclear.
All 3 workflows lack top-level token permissions declarations. No workflow declares top-level write permissions, but explicit least-privilege configuration would improve CI security hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.