The small, licensed package has a clear source tree and no install-time scripts. Organization backing and a GitHub release provide some continuity, but the missing security policy leaves maintenance practices less transparent.
57%
Total Score
75
100
81
75
The latest release was on May 14, 2023, with no releases in the last 12 months and only three releases over nearly five years. This is a meaningful abandonment concern, although the package is not deprecated.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the absence of releases for over three years, this indicates sustained inactivity.
Composer is used as a build tool, providing basic ecosystem-appropriate packaging support. No security scanning tools are configured, which is a modest transparency and hygiene gap.
The linked repository is not archived, but its last push was on May 14, 2023. The active repository status is positive, while the old last-push date aligns with the maintenance concern.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, though this is a transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 103.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.