The source repository is active enough to support the package, with tests, release notes, and security scanning. Recent release and commit activity have stalled, while all eight workflow action references are unpinned.
62%
Total Score
67
100
94
50
The package runs post-install and post-update Composer scripts. These add installation behavior to review, but are not by themselves evidence of abandonment or unsafe dependency quality.
The package has 37 releases since December 2021, but none in the last 12 months and its latest release was about 16 months ago, indicating a meaningful maintenance slowdown.
No commits and no active maintainers were recorded in the last three months, a strong sign of currently stalled development, although the recent repository push partly offsets abandonment concerns.
There are only three open issues and one open pull request, with no new or closed issues or pull requests in the last month; this offers little evidence of current community response.
The repository has no security policy, leaving disclosure and response guidance undocumented; this is a transparency gap for a maintained integration module.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.