This release appears healthy and suitable for dependency consideration: it has a long release history with 110 releases since 2020 and 24 releases in the last 12 months, is stable and not deprecated, and is backed by an active non-archived organization repository. Recent activity is strong, with 155 commits and 36 merged pull requests in the last three months from four active contributors. The package includes a README, tests, a license, and no install-time lifecycle scripts. Remaining concerns are limited to repository security hygiene: no automated security scanning was detected and none of the four workflows declares top-level token permissions, while the repository's 65% top-contributor share warrants monitoring despite organization backing and multiple active contributors.
88%
Total Score
100
100
94
90
Composer build tooling is present, but no security scanning tools were detected; this is a modest repository hygiene gap rather than a standalone adoption blocker.
All 4 workflows lack top-level permissions declarations. No workflow requests top-level write access, but explicitly declaring least-privilege permissions would improve CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
buckaroo/sdk Version ^1.24.3 | — | — |
monolog/monolog Version ^2.9 || ^3.0 | — | — |
magento/framework Version >=103.0.0 | — | — |
magento/module-ui Version ^101.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.