The small codebase has clear release notes, a matching source repository, and no install-time scripts. Maintenance has stopped for about 15 months, with no commits in the last 3 months, and the release has no declared or detected license.
62%
Total Score
75
100
75
83
No declared license, license file, or repository license file was detected, leaving the terms for using and redistributing this package unclear.
The package has four releases over about 23 months, but no releases in the last 12 months; this indicates a small and currently inactive release cadence.
There were no commits and no active maintainers in the last 3 months; combined with no release in about 15 months, this raises maintenance and abandonment concerns.
The repository uses Composer for its build, but no security scanning tools were detected. For this small package, the missing scanning is a modest transparency gap rather than a severe risk.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
hyva-themes/magento2-theme-module Version ^1.3.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.