Organization backing, a clear README, and release notes improve confidence. The long release interval and no commits in three months warrant pinning this version and checking compatibility before upgrades.
68%
Total Score
67
89
75
The package has existed for about four years but made only one release in the last 12 months, with a typical interval of about five months. This suggests slower maintenance, though the recent release shows the project is not abandoned.
There were no commits and no active maintainers in the last three months. Although a release was published recently, the lack of ongoing source activity raises maintenance risk.
Only two issues are open and there are no open pull requests, with no new or closed activity in the last month. The small issue load is positive, but the lack of activity offers little evidence of active maintenance.
The repository uses Composer and Make, showing basic build tooling, but it has no detected security scanning tools. The missing scanning is a modest transparency and hygiene concern.
The repository has no security policy. This does not show a vulnerability, but it leaves reporting and response expectations unclear for a package used in commerce systems.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.0 || ^5.0 || ^6.0 || ^7.0 | — | — |
magento/framework Version ^102.0.4 || ^103.0 | — | — |
magento/module-eav Version ^102.0.4 | — | — |
magento/module-store Version ^101.0.4 | — | — |
magento/module-theme Version ^101.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.