Usable with caveats: this is a clearly licensed, small package with a matching source repository, documented usage, and no deprecation or install-time scripts. It is brand new, has no demonstrated commit history yet, and lacks a security policy, so longer-term maintenance is still unproven.
72%
Total Score
75
100
88
75
The package is extremely new: it has only two releases, both published within hours, so there is not yet enough history to demonstrate sustained maintenance.
There have been no commits or active maintainers in the last three months. Because the repository was only created very recently, this is mainly an unproven-maintenance concern rather than evidence of abandonment.
The repository uses Composer for builds, but no security scanning tool was detected. For a new package this is a transparency and maintenance gap, though it is not by itself severe.
No security policy was found in the repository. That weakens vulnerability-reporting transparency, especially for a package intended for integration into a storefront.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hyva-themes/magento2-default-theme Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.