The package is clearly identified, licensed, and documented for its focused Magento command. Its workflows avoid dangerous triggers and broad token permissions, but their action references are not pinned.
58%
Total Score
67
83
75
The registry lists one maintainer, which is a thin publishing base. The organization-owned repository provides some backing, reducing the concern but not removing the maintenance risk.
Only 3 releases exist, all concentrated in June 2024, with no releases in the last 12 months despite the package being about 811 days old. This is a meaningful maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has been inactive since its last 2024 push.
The repository has 0 stars, 0 forks, and 1 watcher. Low adoption is supporting evidence of limited maturity, but it is not decisive for a small focused module.
No security policy was found in the linked repository. This is a minor transparency gap for reporting vulnerabilities, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.