Workflow checks expose untrusted checkouts and five unpinned actions, though the reported findings are low confidence. The package has tests, release notes, an MIT license, and organizational backing.
58%
Total Score
75
83
100
The package has had no releases in the last 12 months, with the latest release about 14 months ago. Its eight releases over roughly two years show prior activity but do not offset the current pause.
The repository recorded zero commits and zero active maintainers in the last three months, indicating that maintenance has currently stalled.
The linked repository name does not match the package name and its README does not mention this package, leaving uncertainty about whether it is the package's intended source repository.
Both workflows use pull_request_target with untrusted checkouts, and all five analyzed action references are unpinned. The two github-env findings are low confidence, so they add workflow hygiene concern rather than severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
adyen/module-payment Version ^9.13.0 | — | — |
hyva-themes/magento2-theme-module Version ^1.3.11 | — | — |
hyva-themes/magento2-default-theme Version ^1.3 | — | — |
hyva-themes/magento2-hyva-checkout Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.