This is a well-scaffolded, non-deprecated Magento extension with a linked organization-owned repository, documentation, tests, changelog, Composer build tooling, and a read-only CI workflow. However, v2.0.0 is the package's only release and is less than one day old, so there is no demonstrated maintenance history; repository commit activity is also currently absent beyond the initial publication window. Low popularity, no security policy, and no security-scanning tooling add moderate transparency and sustainability concerns, although the package is not archived and its repository README explicitly references the package. It is reasonable to evaluate for adoption with additional project-specific testing, but it does not yet demonstrate the maturity of an established dependency.
68%
Total Score
63
100
83
90
Only one registry account has publish access, which is a thin publishing base. The organization-owned repository provides some backing, so this is a resilience concern rather than a severe health risk.
The package is brand new: it has one release, v2.0.0, with a package age of 0 days and no historical release interval. This provides no evidence of sustained release maintenance yet.
The repository reports zero commits and zero active maintainers over the last three months. Because the package was only published within the assessment window, this is partly explained by its newness, but sustained maintenance remains unproven.
There are no open issues or pull requests and no issue or pull-request activity in the last month. For a package released less than one day ago this is not evidence of neglect, but it also does not demonstrate an established support process.
The repository has 5 stars, 1 fork, and 1 watcher. This is limited adoption evidence, but popularity is supporting evidence and the package is newly released, so it warrants only a modest caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.