The README and changelog make the module’s narrow Magento use case clear, with a small dependency set and organization backing. Pin 1.0.2 only if you can validate it against your Magento version; maintenance and security evidence are dated.
44%
Total Score
50
100
75
75
The package has had no release in nearly five years and no releases in the last 12 months, which is a substantial maintenance concern for a Magento integration.
There were no commits and no active maintainers in the last three months, consistent with the nearly five-year gap since the last repository update.
Three issues and two pull requests remain open, while none were created, closed, or merged in the last month; this suggests unresolved maintenance needs.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap for a package handling inventory behavior.
The repository is not archived, but its last push was nearly five years ago; the unarchived state offers limited compensation for the lack of recent work.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-inventory Version ^1.0 | — | — |
magento/module-inventory-shipping Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.