The package has a clear purpose, matching source repository, and simple installation path. Long-term compatibility is uncertain because maintenance stopped years ago and the repository has no security scanning or policy.
42%
Total Score
25
79
50
The latest release was in December 2016, with no releases in the last 12 months and only two releases overall. This is a substantial abandonment and compatibility concern for a Magento package.
The repository recorded zero commits and zero active maintainers in the last three months, confirming that the long release gap reflects inactive development rather than registry-only publishing delays.
There were no new or closed issues or pull requests in the last month, while seven issues and four pull requests remain open. This suggests unresolved maintenance needs.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning reduces maintenance assurance without proving a security problem.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, especially for a package integrated into an e-commerce platform.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^100.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.