The package includes clear licensing, documentation, tests, and no install-time scripts. Its release history is too new to establish maintenance, and the repository records no commits in the past three months; the missing security scanning is a smaller concern.
68%
Total Score
75
50
86
83
The package declares 41 runtime dependencies and no development dependencies, indicating a substantial integration surface for this storefront component. The count alone is not unsafe, but it increases reliance on the surrounding dependency ecosystem.
This is the package's first recorded release, published within the last day, so there is no demonstrated release cadence or history to support long-term maintenance confidence.
The repository shows zero commits and zero active maintainers over the past three months. Because the package itself is newly released, this is a maintenance-coverage concern rather than proof of abandonment.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not a severe risk on its own.
The repository has no security policy. For a storefront component handling controllers, authentication, payments, and customer flows, that reduces the project's documented security-response transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version ^0.8.1 | — | — |
psr/log Version ^3.0.0 | — | — |
psr/clock Version ^1.0.0 | — | — |
twig/twig Version ^3.29.0 | — | — |
symfony/mime Version ~7.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.