The stable release, clear README, and matching organization repository make the package straightforward to integrate. Its missing security policy and roughly three years without a release or commit leave future maintenance and compatibility uncertain.
60%
Total Score
75
100
88
75
The package has six releases, but none in the roughly three years since July 2023. This is meaningful evidence of stalled maintenance for a shop integration that may need platform compatibility updates.
There were no commits and no active maintainers in the three months measured, consistent with the repository's last push in July 2023. This materially raises abandonment and compatibility risk.
The repository uses Composer for its build, but no security scanning tool was detected. The missing scanning is a modest transparency and maintenance concern, not evidence that the package is unsafe.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. This is a transparency gap, though it is less serious than the stalled maintenance evidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
relevanz/retargeting-base-lib Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.