The repository is not archived and matches the package, with a clear README and a stable release line. However, release activity has stopped for over a year, recent commits are absent, and the license declaration conflicts with the repository license.
18%
Total Score
67
100
69
100
Packagist marks the entire package as abandoned, with no replacement package identified beyond the same package name. This is a severe adoption risk even though the repository remains available.
The artifact declares MIT, while the repository license file is recognized as OSL-3.0. The package is licensed, but the mismatch creates a meaningful transparency and compliance concern.
The package has had no releases in the last 12 months, and its latest release was over a year ago. That indicates weak ongoing maintenance for a migration tool tied to changing Magento versions.
No commits or active maintainers were recorded in the last three months. This supports the conclusion that current maintenance is weak.
There is one open issue but no issue or pull-request activity in the last month. This is limited evidence of active support and adds to the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 103.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.