The linked organization repository is not archived and matches the package, with a useful README and changelog. Release history is sparse, recent commit activity is absent, and the declared MIT license conflicts with the repository's OSL-3.0 license.
22%
Total Score
75
69
50
The package is marked abandoned at the registry for the whole package, with a replacement listed. This is a severe dependency risk even though the linked repository remains available.
The artifact declares MIT and includes a license file, but the repository license is detected as OSL-3.0. This mismatch creates a meaningful licensing ambiguity for consumers.
Only 3 releases exist over about 5 years, with no release in roughly 17 months and no releases in the last 12 months. That indicates a sparse and currently stalled release cadence.
There were no commits and no active maintainers in the last 3 months. That weakens evidence of ongoing maintenance despite the recent repository push.
The repository uses Composer, appropriate for this package, but reports no security-scanning tooling. This is a minor hygiene gap rather than a standalone dependency blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
qoliber/m2-datapatchcreator Version * | — | — |
markshust/magento2-module-simpledata Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.