Extensive documentation, tests, and a matching repository make integration clearer. The project is new, has only one release, and nearly all recent commits come from one contributor; pin this version while its maintenance record develops.
72%
Total Score
83
90
83
The package is only 68 days old and has one release, so its maintenance track record is limited despite the recent publication.
Two maintainers were active, but one contributor made 202 of 203 recent commits. Organization backing provides some handoff capacity, but the observed activity remains highly concentrated.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a package handling commerce functionality.
The single workflow was fully audited with no reported findings or untrusted checkout paths, but all five action references are unpinned and the workflow has top-level write permissions. With no untrusted trigger or sink, this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
craftcms/commerce Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.