Licensing, release notes, and the focused dependency set make the package straightforward to evaluate and integrate. Pin 1.0.0 while watching for a follow-up release, because the project is still young.
68%
Total Score
75
100
88
75
This package is 143 days old and has only one release, so there is little release history to demonstrate maturity or sustained maintenance.
There were zero commits and zero active maintainers in the last three months. For a package only 143 days old, that leaves limited evidence of ongoing maintenance.
The repository uses Composer build tooling, supporting a conventional package build, but no security scanning tools were detected, leaving a modest transparency gap.
No repository security policy was found. This is a minor transparency gap for reporting vulnerabilities, not evidence that the package is unsafe.
The single workflow was fully analyzed with no untrusted checkout, script injection, or audit findings, but it uses a top-level write token and its one action reference is unpinned. These are workflow hygiene concerns, not severe risks without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-customer Version ^103.0 | — | — |
byte8/module-vat-validator Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.