The package includes a usable README, release notes, and no install-time scripts, which helps consumers understand and install it. Its missing license, single maintainer, and absent security policy reduce transparency and long-term confidence.
43%
Total Score
25
71
83
This package has only one release, published more than six years ago, with no releases in the last 12 months. That strongly increases abandonment and compatibility risk for a Magento dependency.
The repository recorded no commits and no active maintainers in the last three months, following a last push in January 2021. The long period without development is a substantial maintenance concern.
No registry declaration, license file, or repository license file was detected. This creates a real legal and transparency gap for adoption.
Only one account has registry publish access. The linked repository is user-owned rather than organization-backed, so there is little visible redundancy if the maintainer becomes unavailable.
Composer build tooling is present, but no security-scanning tool was detected. That weakens automated oversight, with the impact partly outweighed by the package's small, straightforward file tree.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.