Usable with caveats: the module is clearly packaged, licensed, documented, tested, and not deprecated or archived. However, it has only one release and no recorded commits or active maintainers in the last three months, so ongoing maintenance is unproven.
62%
Total Score
50
100
81
90
The registry namespace and repository owner match, which supports that the linked repository backs this package. The owner is an individual account rather than an organization, so the single-publisher base remains a modest continuity concern.
This is a young package with only one release, published about 7 months ago, so there is little release history to demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, leaving current maintenance capacity unproven for a module that may need compatibility updates.
There has been no issue or pull-request activity in the last month. With only one release, this is limited evidence rather than proof of abandonment, but it does not demonstrate active support.
Composer is used as the build tool, but no security-scanning tooling is present. This is a modest transparency and maintenance gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0.4 | — | — |
magento/module-cms Version ^104.0.0 | — | — |
magento/module-cron Version ^100.4.0 | — | — |
magento/module-store Version ^101.1.0 | — | — |
magento/module-config Version ^101.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.