The package has had no release or commit activity for about 18 months, and its license metadata conflicts with the MIT license file. It remains a stable, non-deprecated module with a matching source repository, organization backing, and clear installation documentation.
62%
Total Score
75
100
79
75
The artifact includes a license file recognized as MIT, so the release is licensed, but the manifest declares it as proprietary; that mismatch reduces transparency and should be resolved before adoption.
The package has only three releases and none in the last 12 months; the latest release was about 18 months ago, which raises maintenance risk for a Magento integration.
There were no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The repository uses Composer for its build, but no security scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear for a package used in an administrative Magento context.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-backend Version * | — | — |
hyva-themes/module-magento2-admin Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.