The package has a long release history and was updated recently, with a simple dependency profile and clear licensing. Maintenance is concentrated in one contributor, and the repository has no security policy, leaving some continuity and transparency concerns.
70%
Total Score
67
100
86
75
All 2 recent commits came from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown, so continuity remains concentrated.
The repository received 2 commits in the last 3 months, showing some recent activity, but the pace is light for a maintained project. For a generated translation package, this is adequate but not strong.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. The absence is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy. This matters less for a small generated language-data package than for an application library, but it still reduces transparency about vulnerability reporting.
Version 0.0.69 is not a prerelease, and no recent releases are prereleases. The 0.x major version still signals an API that may not promise long-term stability.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.