X-Magento-Vary Cookie Signer
58%
Total Score
caution
Usable with caveats: releases stopped nearly two years ago and the repository has no recent commits.
The latest release was in November 2024, with no releases in the last 12 months; this is a meaningful sign of slowing maintenance for a dependency.
There were no commits or active maintainers in the last three months, reinforcing the concern raised by the absent recent releases.
The repository name does not match the package name and its README does not mention the package, so the source-to-package relationship is less clear than expected.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and maintenance expectations less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.5 <130.0.5-p5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.