The package includes a usable README and has no install-time scripts. Its license records disagree, and the repository has no security scanning or security policy.
40%
Total Score
58
50
The latest release was published about 7 years ago, with no releases in the last 12 months. That long gap is strong evidence of abandonment risk despite 12 historical releases.
A license file is present, but it identifies MIT while the manifest declares LGPL-2.1. This mismatch reduces transparency about the terms governing the release.
Composer is used for the build, but no security-scanning tooling is present. That weakens maintenance hygiene, although it is not evidence that the package is unsafe by itself.
The repository is not archived, which is a modest compensating signal, but its last push was about 6 years ago and does not offset the stale release history.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap for a library handling shipping integrations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
simexis/omniship Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.