The source repository is current and the release is stable, with a clear README and changelog. The license metadata conflicts with the repository license, so provenance should be clarified before adoption.
22%
Total Score
83
75
75
Packagist marks the entire package as abandoned and identifies qoliber/m2-attribute-pagination as the replacement. Package-level abandonment is a severe dependency risk even though the replacement repository is available.
The manifest declares MIT, while the repository license files were detected as OSL-3.0. Both provide licensing, but the mismatch creates uncertainty about the terms applying to this release.
There were no commits and no active maintainers in the last 3 months. The repository was nevertheless pushed recently and the registry has a recent release, so this is a maintenance caution rather than proof of abandonment.
The repository uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a modest hygiene gap, while Composer support fits this package's ecosystem.
The repository has no security policy. That reduces transparency for vulnerability reporting, although the package is small and the absence alone is not a severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.