Usable with caveats: it is a young, actively released Magento module with a matching organization-owned repository and clear packaging. However, the repository shows no commits or active maintainers in the last three months, has no tests or security policy, and has no automated security scanning.
68%
Total Score
83
100
83
90
A substantial README and changelog are present, but neither the package nor repository contains tests. For a Magento module affecting product, cart, and checkout behavior, the absence of tests is a real maintenance and regression concern.
The repository records zero commits and zero active maintainers over the last three months, despite a recent push and recent package releases. That gap weakens confidence in sustained maintenance and warrants caution.
The repository has zero stars and watchers and one fork. This is weak supporting evidence for adoption, but popularity is not decisive for a young, specialized package.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. For a Magento extension that runs in administrative, storefront, cart, and checkout contexts, this reduces the available process evidence for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-page-cache Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.