The MIT license and matching repository provide useful transparency. One maintainer and a very small project limit visible maintenance capacity, while unpinned workflow actions add a modest supply-chain hygiene concern.
61%
Total Score
67
83
50
The registry lists one maintainer, which creates a thin publishing base. The organization-owned repository provides some backing, so this is a limitation rather than a severe risk.
Only two releases exist, with no release in the last 12 months and a latest release in April 2025. That sparse, aging release history raises maintenance uncertainty for a Magento module.
The repository recorded zero commits and zero active maintainers in the last three months. This is direct evidence of currently inactive development, although the repository is not archived.
No security policy was found in the repository. This is a transparency and vulnerability-reporting gap, though it is a hygiene concern rather than evidence that the package is unsafe.
Both analyzed workflows use job-level permissions and have no untrusted checkouts or injection findings, but both of the two action references are unpinned. That leaves avoidable action-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.