The MIT license, matching repository, and small Composer package structure make it easy to inspect and adopt. No security policy or scanning is present, and the project has not shown recent maintenance, so newer Magento compatibility may lag.
57%
Total Score
50
88
83
Only one registry maintainer account is listed, leaving little visible publishing redundancy. The matching repository and package ownership provide some context but do not establish a broader maintainer base.
The package has four releases since July 2020, but its latest release was in December 2023 and it had no releases in the last 12 months. This is a meaningful maintenance concern for a package tied to a fast-moving platform.
There were no commits and no active maintainers in the measured three-month period. Combined with the old last push, this indicates inactive maintenance rather than merely a quiet release schedule.
Composer is used as the build tool, which fits the package, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.