Usable with caveats: the repository is active, organized, and backed by an organization, but version 2.0.0 has had no registry release for nearly three years. Missing security documentation and workflow permission declarations add smaller transparency concerns.
68%
Total Score
100
100
88
80
The package has 30 releases and a historically regular median interval of about 14 days, but the latest registry release was on 2023-10-07 and there were no releases in the following 12 months. This is a meaningful release-maintenance concern, partly offset by recent repository commits.
The repository uses Composer and Make for build-related work, supporting repeatable project maintenance, but no security scanning tools were detected.
No repository security policy was found. This is a transparency gap for a plugin handling customer downloads, although it is not evidence that the package is unsafe.
Both analyzed workflows lack top-level token permission declarations. No workflow requests top-level write access, which limits the concern, but explicit least-privilege settings would improve CI transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.5.2 | — | — |
shopware/storefront Version ~6.5.2 | — | — |
shopware/administration Version ~6.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.