The repository has no commits or active maintainers in the last three months, and it lacks a security policy. Frequent releases and organization backing provide some maintenance evidence, but the repository-to-package name mismatch makes ownership less clear.
62%
Total Score
67
100
83
50
The repository recorded zero commits and zero active maintainers during the last three months. That is a meaningful maintenance concern, especially alongside the absence of recent issue or pull-request activity.
There were no new or closed issues and no new or merged pull requests in the last month, with no open issues or pull requests. This indicates little visible community or maintainer activity, though the package may be stable and organization-backed.
The repository name does not match the package name, and no README package mention was available. This weakens confidence that the linked repository directly documents this package, although a subpackage or plugin repository can use a different name.
Composer is used as a build tool, which fits this Magento package, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of unsafe code.
The repository has no security policy. That reduces vulnerability-reporting transparency, although it is not by itself evidence that the package is unmaintained.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102.0.0 || ^103.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.