The package includes tests, a substantial README, a changelog, and a matching MIT license. Its source repository has had no commits or active maintainers for about five years, with no recent releases and no security policy, so ongoing support is a significant concern.
42%
Total Score
0
71
75
The package is about five years old with 106 releases, but it has had no releases in the last 12 months and its latest release was published about five years ago. This strongly raises abandonment risk despite the earlier release history.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided signal shows current maintenance capacity.
The repository has zero stars, forks, and watchers, providing no supporting evidence of an active user or contributor community. Popularity is secondary, but this reinforces the maintenance concern.
The linked repository is not archived, which is a positive sign, but its last push was about five years ago. The active repository status does not compensate for the lack of recent work.
The repository has no security policy. For a substantial e-commerce package, that is a transparency gap, and no other provided signal shows an established vulnerability-reporting process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ~1.2 | — | — |
doctrine/dbal Version ~2.5 | — | — |
aimeos/ai-gettext Version 2021.07.* | — | — |
aimeos/ai-laravel Version 2021.07.* | — | — |
laravel/framework Version ^6.20.12||^7.30.4||^8.40.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.