This release appears usable and reasonably transparent, with an MIT license, complete package documentation and tests, a changelog, a matching source repository that mentions the package, read-only workflow permissions, and a security policy. However, it is extremely new, with only two releases and no measurable three-month commit activity, so long-term maintenance and compatibility are not yet demonstrated. The organization-backed repository and recent push partially offset the immaturity, but this should be adopted with normal caution until a longer maintenance history is established.
68%
Total Score
88
100
89
100
The package is only about 0 days old and has two releases, with releases separated by roughly 5 hours; this provides almost no evidence of sustained maintenance or release discipline.
The repository records zero commits and zero active maintainers over the last three months, a meaningful maintenance concern; the very recent repository push and release partially explain this result but do not demonstrate sustained activity.
Composer build tooling is present, but no security-scanning tools were detected. The repository's SECURITY.md and read-only workflow permissions provide some compensating hygiene, so this is a moderate rather than severe concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.