The repository includes tests and a changelog, but no security policy or automated security scanning. Its workflows leave all six actions unpinned, adding maintenance hygiene risk.
55%
Total Score
50
83
75
This is the package's only release, published about 19 months ago, with no releases in the last 12 months. That leaves maintenance continuity and future support uncertain.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the one-release history and raising abandonment risk.
The repository has 0 stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external sign of adoption or review.
Composer build tooling is present, but no security-scanning tools are configured. The missing automated security check is a modest transparency and maintenance gap.
The linked repository has no security policy. For a package handling Shopify API communication and webhooks, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^8.0|^9.0|^10.0|^11.0 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
illuminate/routing Version ^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0 | — | — |
illuminate/contracts Version ^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.