Documentation and release notes are thorough, and the repository has organizational backing plus a security policy. Maintenance is currently concentrated in one contributor, while the project has no automated security scanning.
76%
Total Score
83
100
94
100
All 9 commits in the last 3 months came from one contributor, giving the project a concentrated current contributor base. The organization-owned repository provides some handoff capacity, but this remains a maintenance resilience concern.
Composer build tooling is present, but no security scanning tools were detected. For a commerce integration handling control-panel and webhook workflows, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verbb/base Version ^3.0.18 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
pelago/emogrifier Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.