Clear documentation, release notes, and a security policy improve transparency. The package has a focused seven-dependency profile and no install-time scripts, though maintenance depends heavily on one recent contributor.
78%
Total Score
75
100
94
100
All 26 recent commits came from one contributor, concentrating maintenance knowledge and creating a meaningful continuity risk. Organization backing partly reduces the risk of an individual departure.
The repository has 22 open issues and recorded no issue or pull-request activity in the last month. This is a maintenance concern, although recent commits and releases provide compensating evidence.
Composer is used for builds, but no security-scanning tool was detected. This is a modest transparency and prevention gap, not evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verbb/base Version ^3.0.19 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
verbb/shippy Version ^1.2.23 | — | — |
dvdoug/boxpacker Version ^3.0 | — | — |
craftcms/commerce Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.