Healthy and suitable to use, with one maintenance caveat: the package has frequent recent releases, clear source backing, tests, and release notes, but only two commits from one contributor in the last three months. The organization ownership reduces the risk from that concentrated activity, though the repository lacks a security policy and explicit workflow permissions.
78%
Total Score
75
100
94
75
One contributor made all two commits in the last three months, creating concentrated recent activity. Organization ownership provides some handoff capacity, so this is a caution rather than a severe risk.
Only two commits were recorded in the last three months, indicating low recent source activity despite 30 releases in the last year. This is a maintenance caution, though releases may be produced through a workflow not reflected in the sampled commits.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a modest transparency gap for a payment integration.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting expectations unclear.
The only workflow does not declare top-level token permissions. No write permissions were detected, but explicit least-privilege configuration would provide stronger assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.7.0 | — | — |
unzerdev/php-sdk Version ~4.0.0 | — | — |
shopware/storefront Version * | — | — |
shopware/administration Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.