Usable with caveats: it is actively published and backed by an organization, but this is an eight-day-old security module with all six recent commits from one contributor. The proprietary license and lack of security policy or scanning also reduce transparency.
60%
Total Score
83
100
81
90
The manifest declares a proprietary license, and no license file was found in either the package or repository. That creates a real legal and transparency concern for a package described as open source.
The package is only 8 days old, with 4 releases and a median interval of about 8 hours. This shows active early development but provides little evidence of long-term maintenance or compatibility stability.
One contributor made all 6 recent commits, leaving no demonstrated individual backup. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository uses Composer, appropriate for this PHP package, but it has no security-scanning tooling. For a security-focused module, that missing verification layer is a meaningful hygiene gap.
No SECURITY.md or equivalent security policy was found. For a module intended to mitigate vulnerabilities, the absence of a stated reporting and response process lowers transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
magento/module-email Version >=101.1.0 | — | — |
magento/module-sales Version >=103.0.0 | — | — |
magento/module-graph-ql Version >=100.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.