Healthy and actively maintained, with strong release and commit activity and a clear repository match. Review the install script and workflow permissions before adopting, and note the small maintainer base and lack of a security policy.
78%
Total Score
67
93
50
The package runs a post-autoload-dump install-time script. This adds install complexity and should be reviewed, although the signal does not show a destructive or clearly unsafe action.
The package and repository are owned by the same named individual, but the repository owner is a user rather than an organization. This supports clear ownership while offering less institutional continuity.
The top contributor made 72% of recent commits, creating some concentration risk, but two other contributors were active and one supplied 26% of commits. This is a maintenance concern rather than a severe single-person failure risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency gap for a package handling e-commerce functionality, though it is not evidence of maliciousness.
No repository security policy was found. This makes vulnerability reporting and maintenance expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dmi3yy/ddocs Version ^1.0 | — | — |
seiger/stask Version ^2.0 | — | — |
seiger/sgallery Version ^1.5 | — | — |
evolution-cms/evolution Version ^3.5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.