This is a coherent, licensed Composer plugin with a complete-looking 41-file artifact, an organization-owned and matching repository, stable version 3.0.0, no deprecation, and no workflow or lifecycle-script risks detected. However, it was released only today, has no demonstrated release history or commit activity beyond initial publication, has no tests, security policy, or security-scanning tooling, and has no adoption evidence; those gaps make maintenance and operational confidence limited for a plugin that modifies installed Magento code during Composer operations. It may be usable when the patch is urgently required, but dependency adoption should include independent review of the patch contents and a plan to move to an upstream fixed Magento release.
58%
Total Score
67
100
78
90
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.