Its licensing, repository ownership, and minimal Composer dependency make the package easy to place in a project. However, it has had no release or commit activity since November 2020, and the repository does not identify the package in its README. Pinning this release is safer than expecting ongoing updates.
43%
Total Score
50
100
50
The package has only three releases, all clustered in November 2020, with no releases in nearly six years. This is strong evidence of abandonment risk, although the package may be intentionally static.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This lowers confidence that defects or ecosystem changes will be addressed.
The repository name does not match the full package name, and its README does not mention this package. That makes the package-to-source relationship less transparent, even though a name difference can occur in related package layouts.
Version 0.0.3 is not a stable-major release, so its maturity and compatibility guarantees are limited. The absence of prerelease labeling provides only a small offset.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.