Usable with caveats: it is a licensed, stable Magento module with a linked repository and recent releases, but it is only 62 days old and all recent commits come from one contributor. The repository also lacks security scanning and a security policy, so review it before production use.
62%
Total Score
50
100
88
88
The registry namespace and repository owner align around BotPenguin, and the repository owner is a user account rather than an organization. The package therefore has identifiable project backing but no organizational handoff capacity shown.
The package is young at 62 days, with only two releases and a median interval of about 22 days. That shows recent delivery but provides limited evidence of long-term maintenance.
One contributor made 100% of the three recent commits, creating a meaningful single-maintainer continuity risk. The repository owner is not identified as an organization, so there is no provided organizational backing to offset this concentration.
There were three commits in the last three months, showing some recent activity, but only one active maintainer carried it out.
There are no open issues or pull requests, but there is also no recent issue or review activity. For this very young project, that is limited evidence rather than a severe concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-cron Version ^100.4 | — | — |
magento/module-quote Version ^101.2 | — | — |
magento/module-sales Version ^103.0 | — | — |
magento/module-store Version ^101.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.