The package is focused, documented, licensed, and has a repository matching its README and artifact. Single-person ownership, no security policy, and limited repository activity reduce confidence in long-term maintenance.
62%
Total Score
50
100
88
75
Only one registry account has publishing access, leaving limited publishing redundancy. The repository is user-owned rather than organization-backed, so there is no provided backing signal to offset that thin maintainer base.
Five releases arrived within roughly six days, showing active initial publishing but not an established maintenance pattern. The package is only 117 days old, so its longer-term reliability is still unproven.
The repository recorded zero commits and zero active maintainers in the last three months, despite the release being only about four months old. That sustained inactivity is a meaningful maintenance concern.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tool is configured. The missing scan is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This matters for a Magento module used in deployed applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gdw/core Version ^4.4 | — | — |
magento/framework Version >=103.0.4 <104.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.