Its documentation is substantial, and the package has a clear license with a small runtime dependency surface. The main reservation is limited recent development activity and no published security policy.
78%
Total Score
75
100
94
83
Only one commit was recorded in the last three months, by one active maintainer. The recent release offsets this somewhat, but ongoing development activity is limited.
There are 34 open issues and three open pull requests, but no issues or pull requests were opened or closed in the last month. This suggests limited current issue-management activity.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a transparency and hygiene gap rather than evidence of unsafe code.
The repository has no published security policy. That leaves vulnerability-reporting and response expectations unclear for a package used in Magento projects.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-catalog-import-export Version ^101.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.