The package is clearly licensed, documented, and backed by a non-archived organization-owned repository. Its single maintainer, no security scanning, and no commits in the last three months leave less evidence of ongoing maintenance.
68%
Total Score
75
100
89
83
The repository recorded zero commits and zero active maintainers in the last three months. Because this is a maintained plugin with recent releases, the lack of recent source activity is a meaningful maintenance concern.
The repository has zero stars, one fork, and one watcher, indicating limited community adoption. Popularity is supporting evidence only, so this modestly reduces confidence rather than deciding the assessment.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap for a plugin handling storefront and email functionality, though it is not evidence of abandonment by itself.
No repository security policy was found. This weakens disclosure transparency, but the gap is not severe enough to make the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.