The package is clearly structured for Magento and includes a useful README, a matching source repository, and organization backing. Its only release was about 1 year 11 months ago, with no recent commits, while the license declaration conflicts with the MIT license file.
55%
Total Score
83
100
78
83
The artifact includes an MIT license file and the repository also has one, so the release is licensed. However, the manifest declares it as proprietary while the detected license is MIT, creating a transparency mismatch.
This is the package's only release, published about 1 year 11 months ago, with no releases in the last 12 months. That makes ongoing maintenance uncertain for a Magento module.
There were no commits and no active maintainers in the last three months. Combined with the single-release history, this is meaningful evidence of inactive maintenance.
The repository uses Composer build tooling, which fits the package ecosystem. No security scanning tooling is present, a modest process gap but not a severe dependency risk by itself.
The linked repository is not archived, although its last push was about 1 year 11 months ago, consistent with the stale release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-backend Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-indexer Version * | — | — |
hyva-themes/module-magento2-admin Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.