Clear licensing, documentation, and package-to-repository alignment make adoption easier. The single-user project has no recent commits or releases, while workflow dependencies are unpinned and include archived actions.
58%
Total Score
50
93
50
The latest release was about 4 years ago, with no releases in the last 12 months. That is meaningful abandonment risk for a Shopware plugin, although the five-release history shows it was previously maintained.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap. This lowers confidence that compatibility or defects will be addressed promptly.
The repository has no security policy. For a plugin that handles storefront redirects, this weakens the project's vulnerability-reporting transparency, though it is not evidence of a security defect.
All 6 workflow action references are unpinned, and two high-confidence medium-severity findings use archived actions; a low-severity finding also installs a package outside a lockfile. The workflows were fully analyzed and have no untrusted checkouts or script injection.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.