The package is small and clearly scoped, with a matching repository and useful configuration documentation. Composer-only packaging and no install scripts reduce integration risk, but current validation and security oversight are limited.
52%
Total Score
100
63
75
The latest release was about 5 years ago, with no releases in the last 12 months and only three releases overall. The repository is not archived, but the long pause raises abandonment risk.
The package includes a 2,713-character README with configuration examples, which helps consumers integrate it. No tests are present in the package or repository; that is common packaging practice, but it leaves behavior less independently validated.
The repository has 2 stars and 1 fork, indicating a very small user and contributor footprint. Popularity is only supporting evidence, but it provides little evidence of broad community maintenance.
Composer is used as the build tool, but no security-scanning tooling is reported. The simple package structure limits the significance of this gap, though it weakens ongoing assurance.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This matters more for a package that integrates with order and affiliate postback flows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silverstripe/cms Version >=4.0 | — | — |
silverstripe/framework Version >=4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.