The package includes tests, clear installation guidance, and only four runtime dependencies. Its organization-owned repository remains available, but it lacks a security policy and shows limited project activity.
54%
Total Score
75
100
75
50
The latest release was in April 2020, more than six years ago, and there were no releases in the last 12 months. The package has only three releases, which raises maintenance and compatibility concerns.
There were no commits or active maintainers in the last three months. Combined with the old latest release, this indicates that maintenance has effectively slowed or stopped.
Composer is used for the build, which fits the PHP package ecosystem, but no security scanning tools are present. The missing scanning is a hygiene gap rather than evidence of unsafe code.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, particularly for an extension installed in commerce systems.
Version 0.0.3 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-store Version * | — | — |
magento/module-backend Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.