The focused eight-file module has clear usage documentation and no install-time scripts. Organization backing and a single runtime dependency reduce complexity, but ongoing maintenance should not be assumed.
56%
Total Score
75
100
71
83
The package has had only two releases, both in September 2017, with no releases in the last 12 months. This long period without a new release is a meaningful maintenance concern for a dependency.
The repository has no new issues, pull requests, or merged pull requests in the last month, consistent with the package's long inactivity. The absence of open work is mildly reassuring but does not offset the lack of recent development evidence.
The repository has five stars and one fork, indicating limited adoption evidence. Popularity is supporting evidence only, so this modest reach does not independently make the package unsafe to depend on.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are reported. This is a minor transparency gap rather than a severe health issue.
No security policy is present in the repository. For a small focused module this is a hygiene gap, though it provides little evidence about abandonment by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^100.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.