This is a mature, actively released package with 267 releases over more than 10 years, 15 releases in the last 12 months, a stable non-prerelease version, a non-deprecated registry status, and a current unarchived repository owned by the Fastly organization. The artifact is substantial and well documented, with tests, a changelog, Composer build tooling, and a clear BSD-3-Clause license. Recent repository activity is present across three maintainers, although commit volume is modest and several repository security-hygiene gaps remain: no security policy or security-scanning tools, undeclared top-level workflow token permissions, and one workflow flagged for script injection. These warrant review of the CI configuration but do not outweigh the strong maintenance and project-backing evidence.
86%
Total Score
100
100
94
70
One of four analyzed workflows, delete-bot-branch.yaml, was flagged for script injection. This is a concrete CI hygiene concern, although no pull_request_target, workflow_run, or untrusted-checkout risks were detected.
Composer build tooling is present, supporting reproducible project workflows, but no security-scanning tools were detected, leaving a security-hygiene gap.
The repository has no SECURITY.md or other detected security policy, reducing transparency around vulnerability reporting and response procedures.
All four workflows lack top-level token-permission declarations. No workflow declares top-level write access, but explicitly constraining permissions would provide stronger CI hardening.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-13761 fastly/magento2 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 1.2.26. | 0.0.0 - 1.2.26 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
zordius/lightncandy Version ^1.2 | — | — |
laminas/laminas-http Version ^2.6.0 | — | — |
magento/module-store Version >=101.1.0 | — | — |
magento/module-config Version >=101.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.