Security coverage is thin, with no repository security policy or scanning tools, and the project has only two stars and one registry publisher. The package is small and clearly documented, with organization backing and a matching source repository.
62%
Total Score
75
100
88
83
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance concern, although the assessed version was released recently.
The repository has two stars, zero forks, and zero watchers. Low usage is supporting evidence rather than a verdict, but it provides little external validation or resilience.
Composer build tooling is present, but no security scanning tools are configured. For a plugin that handles remote database synchronization, this leaves an avoidable quality and security-process gap.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, especially for a plugin handling SSH and database operations.
No GitHub Actions workflows were present, so the audit found no workflow risks but also provides no evidence of automated testing, pinned build actions, or release checks. This is a limited process gap rather than a direct workflow hazard.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.6.0 || ~6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.