The package has clear documentation, tests, release notes, and an identified organization-backed repository. Maintenance has slowed substantially, while the workflow uses three unpinned actions and one archived action; the missing security policy adds a smaller transparency gap.
61%
Total Score
75
94
67
The package has 49 releases since May 2022, but none in the last 12 months and its latest registry release was nearly two years ago, indicating stalled publishing activity.
The repository recorded no commits and no active maintainers in the last three months, which is a meaningful sign of currently low maintenance capacity.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The only workflow was fully analyzed with no untrusted checkout or script-injection findings, but all three action references are unpinned and one uses an archived action, creating avoidable workflow maintenance risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-eav Version * | — | — |
magento/module-store Version * | — | — |
magento/module-config Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-elasticsearch Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.