Usable with caveats: it is actively maintained and backed by an organization, but the package is only 96 days old and the linked repository does not identify or mention this package. Review the source and publishing setup before relying on it in production.
68%
Total Score
88
100
78
75
The package is young at 96 days and has only three releases, with a median interval of about 48 days. That provides some release evidence but limited history for judging long-term maintenance.
The repository received one new issue in the last month and merged one pull request, but the issue remains open. This shows some activity while leaving limited evidence of issue follow-through.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish that this repository is the package's authoritative source. This is a meaningful provenance concern despite the organization backing.
The repository has one star and one fork, indicating little external adoption. Popularity is only supporting evidence, so this lowers confidence in maturity but is not a severe concern by itself.
The repository uses Composer for builds, but no security scanning tools were detected. The build setup is appropriate, while the missing scanning is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ^6.7.0 | — | — |
shopware/storefront Version ^6.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.