Licensing is clear, the package is small, and its single runtime dependency is explicit. The organization-owned repository remains available, but ongoing maintenance and security-policy coverage are limited.
64%
Total Score
67
100
88
75
The package has 28 releases since May 2019, but none in the last 12 months; the latest release was about 14 months ago. This suggests slowing maintenance, despite a substantial release history.
There were no commits and no active maintainers in the last three months. Combined with no release in about 14 months, this is evidence of limited current maintenance.
There has been no issue or pull-request activity in the last month, with one issue still open. This is a modest maintenance concern, though the small package scope limits its weight.
Composer is used for the build, providing basic project tooling, but no security-scanning tool was detected. For a small translation package this is a minor transparency gap.
The repository has no published security policy. This weakens security-reporting transparency, although the package is a narrow language-data artifact.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.