Tests, a changelog, clear licensing, and organization backing make the release transparent to maintain. CI leaves all six actions unpinned, and the repository has no security policy or scanning, so its security hygiene is incomplete.
82%
Total Score
100
100
94
83
Composer build tooling is present, but no security scanning tools are reported. That leaves a preventable gap in the project's visible maintenance and dependency-hygiene practices.
The repository has no security policy file. This is a modest transparency gap for a package that runs inside an administrator-facing Magento installation, though it does not by itself indicate abandonment.
The only workflow was fully analyzed with no untrusted checkout, script injection, or high-confidence findings, and it does not use broad top-level write permissions. However, all six action references are unpinned, leaving CI exposed to changes in referenced actions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-ui Version ^101.2 | — | — |
magento/module-cms Version ^104.0 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-config Version ^101.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.