The stable version, clear license, matching repository, and recent repository push provide useful reassurance. The absent security policy and all eight unpinned workflow actions leave notable transparency and build-integrity gaps.
62%
Total Score
67
100
83
75
The package has five releases over about 27 months, but none in the last 12 months; that weakens confidence that fixes will arrive promptly.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance warning despite the more recent push timestamp.
There are two open issues and one open pull request, but no issues or pull requests were opened or merged in the last month, suggesting limited current interaction.
The repository has zero stars and one fork, indicating limited visible adoption. This is supporting caution rather than a decisive health problem for a specialized extension.
Composer build tooling is present, but no security-scanning tools were detected, leaving an avoidable assurance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=100.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.