The repository is active enough to be identifiable, unarchived, and backed by tests, a changelog, and a clear license. Missing security policy and five unpinned workflow actions reduce transparency and build confidence.
58%
Total Score
33
100
86
75
There were zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package only 148 days old.
The repository is owned by a personal GitHub account rather than an organization, so there is no demonstrated organizational backing to offset the thin recent maintenance record.
The package is young at 148 days, with six releases concentrated in roughly one day; this shows initial publishing activity but not a proven long-term cadence.
The repository has one open issue and three open pull requests, with two new pull requests but no merges in the last month; this suggests some activity but limited demonstrated follow-through.
Composer is used as the build tool, but no security scanning tools are reported, leaving a modest gap in ongoing project hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 103.0.* | — | — |
magento/theme-frontend-luma Version 100.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.