Package Health

davidbel/magento-ai-search

AI search module for Magento 2.

Latest v1.0.2PackagistPackagist

70%

Total Score

caution

Usable with caveats: all recent commits come from one contributor and workflow actions are unpinned.

Health Score Breakdown

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-contributor activity and registry maintainer base provide limited evidence of organizational continuity.

Repo bus factorcaution

One contributor made all 150 commits in the last three months, leaving no demonstrated handoff capacity if that contributor becomes unavailable.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. For a package that handles remote AI integrations, this is a meaningful repository hygiene gap.

Workflow auditcaution

Both workflows were analyzed without audit findings or unsafe-trigger sinks, and one uses read-only permissions. However, all 7 action references are unpinned and one workflow has top-level write permissions, creating avoidable build-integrity and token-scope concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

David Belicza

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1 || ^2.0 || ^3.0
—
—
psr/http-message
Version ^1.1 || ^2.0
—
—
guzzlehttp/guzzle
Version ^7.5
—
—
magento/framework
Version 103.0.*
—
—
magento/module-ui
Version 101.2.*
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform