This is a mature, actively maintained and transparently published module: it has existed since 2016, is on a stable major release, is not deprecated, has a current repository push, recent commits and pull-request activity, tests, a license file, build tooling, Dependabot, and no detected dangerous workflow patterns. The main reservations are a concentrated recent contributor base, no repository security policy, and workflows without explicit top-level token permissions; these are meaningful hygiene concerns but are moderated by PrestaShop organization ownership, ongoing activity, and the absence of top-level write permissions. The package appears suitable to depend on, with normal supply-chain review recommended.
85%
Total Score
90
100
100
80
Recent activity is concentrated: the top contributor made 87.5% of commits and only two contributors were active. This is a caution, although organization ownership provides some capacity for maintenance handoff.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting and response expectations less transparent.
All three workflows lack top-level permissions declarations. No workflow declares top-level write access, which limits the concern, but explicit least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.