Clear documentation and tests make the package easier to integrate, while its young history leaves less evidence of long-term stability. The small audience and lack of repository security tooling add modest transparency concerns.
77%
Total Score
100
50
83
83
The package has nine runtime dependencies, including several Magento modules and its companion feed package. The breadth is expected for a Magento integration but increases compatibility surface compared with a small standalone library.
There have been three releases over a package age of about five months, with the latest release roughly two and a half months before collection. This is reasonable early activity but provides limited long-term maintenance evidence.
The repository has three stars, no forks, and no watchers. This indicates limited external adoption, but popularity is supporting evidence and does not outweigh the matching source, tests, and release evidence.
Composer build tooling is present, but no repository security-scanning tools were detected. That is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is not by itself evidence of abandonment or unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-store Version * | — | — |
magento/module-backend Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-sales-rule Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.