Its exact, licensed nine-file repository and organization ownership provide useful traceability. There is no security policy or scanning, and the single registry maintainer leaves little visible support capacity.
38%
Total Score
50
71
83
The package has had only two releases, both in August 2019, with no releases in the last seven years. That strongly raises abandonment risk, although the registry does not mark it deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent releases. The repository is not archived, but current maintenance is not observable.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling was found. This is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear for a package that changes Magento behavior.
The latest version remains 0.0.1 and is not a stable major release, which signals limited maturity. The small, focused package scope partly offsets the concern but does not address its age.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.