The repository has no recent commits or active maintainers, and the package has no declared or detected license. Its source repository does not match the package name, leaving ownership and maintenance less clear.
42%
Total Score
50
50
No license is declared, and neither the package nor the linked repository contains a license file. That leaves the legal terms for using the dependency unclear.
The package has made 7 releases, but none in the last 12 months; its latest release was in September 2024. This is meaningful abandonment risk for a dependency, despite the stable version series.
The linked repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's lack of recent releases. The repository is not archived, but there is no observed current maintenance.
The repository name does not match the package name, and no README mention was available. This weakens confidence that the linked repository is the package's actual maintained source.
The repository uses Composer, which fits the package ecosystem, but reports no security-scanning tools. This is a minor transparency and maintenance gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=102.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.