The README, release notes, and lightweight dependency set make the package easy to evaluate. There is little formal security process, so future maintenance and release quality depend heavily on the current project owner.
68%
Total Score
75
100
83
75
The manifest declares MIT, while the repository license file is detected as OSL-3.0. The release is licensed, but the mismatch creates legal uncertainty for adopters.
One contributor made all 14 commits in the last 3 months, giving the project a bus factor of one. This concentrates maintenance and release continuity in a single person.
The repository has one star, no forks, and no watchers, providing little external evidence of review or adoption. Popularity is only supporting evidence, so this modestly limits confidence rather than determining the verdict.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a modest process gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for an extension that handles tracking-related customer data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.