Its stable 1.0.0 artifact is small, focused, licensed MIT, and has only one runtime dependency. Organization backing and a matching repository help, but the project has no security policy and provides little evidence of ongoing care.
52%
Total Score
50
100
75
83
The package has only one release, published about three years ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a dependency.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this indicates little recent maintenance.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest transparency gap.
The linked repository is not archived, but its last push was about three years ago, so the non-archived status offers limited reassurance.
The repository has no security policy. For a small development-focused plugin this is a moderate transparency gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
shopware/core Version ~6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.