Usable with caveats: it has a stable release, clear package contents, an explicit license, and organization-backed source, but maintenance appears to have stalled since March 2025. The repository also does not mention this package by name, and it lacks security scanning and a security policy.
58%
Total Score
50
100
81
83
There were no commits and no active maintainers in the last three months. Combined with no release in about 18 months, this is the clearest abandonment concern.
The package has 14 releases since July 2020, but no releases in the last 12 months; its latest release was about 18 months ago. This indicates a meaningful maintenance slowdown for a Magento integration.
The repository name differs from the package name and its README does not mention the package. A name mismatch can be normal for a module repository, but the lack of any README reference leaves some uncertainty that the linked repository is the package's intended home.
The repository uses Composer, showing basic build tooling, but has no security scanning tools. The missing scanning is a transparency and maintenance gap for a package integrated into an ecommerce platform.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is a hygiene concern rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dnafactory/core Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.