No releases have followed the June 2024 launch, and the repository has had zero commits or active maintainers for the last three months. Tests, release notes, licensing, and automated security scanning provide useful evidence, but they do not offset the abandonment risk.
12%
Total Score
25
67
50
This package has only one release, published 824 days ago, with no releases in the last 12 months. That leaves consumers without evidence of an ongoing release or maintenance process.
The repository recorded zero commits and zero active maintainers in the last three months. This strongly reinforces the abandonment concern rather than showing merely slow development.
The linked repository is archived, despite being pushed as recently as April 2025. An archived source project is a severe abandonment risk for a package intended to run an e-commerce application.
There are 73 open issues and 8 open pull requests, with no new or closed issues or merged pull requests in the last month. The unresolved backlog and lack of recent response indicate weak ongoing support.
The repository has no SECURITY.md policy. For an e-commerce application handling payments and user data, the missing vulnerability-reporting guidance is a genuine transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^4.0 | — | — |
doctrine/dbal Version ^3.0 | — | — |
dompdf/dompdf Version 2.0.4 | — | — |
predis/predis Version ^2.2 | — | — |
konekt/concord Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.