The MIT license, matching source repository, and organization ownership provide clear provenance. The package has no tests or README in the published artifact, no security policy or scanning, and its source has been inactive since November 2022.
40%
Total Score
50
75
75
Only two releases were published, both in November 2022, with no release in the last 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package's long release gap and indicating substantial abandonment risk.
The package has no README, tests, or changelog, although absent tests and changelogs are normal for published artifacts and a GitHub release exists for this version. The missing README still reduces consumer documentation for this integration module.
Composer is used for the build, but no security-scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence of an unsafe release by itself.
The linked repository has no security policy, leaving vulnerability-reporting expectations and maintainer response procedures unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
ghostunicorns/module-crt-base Version ~1.0.0 | — | — |
ghostunicorns/module-crt-amqp-refiner Version ~1.0.0 | — | — |
ghostunicorns/module-crt-amqp-collector Version ~1.0.0 | — | — |
ghostunicorns/module-crt-amqp-transferor Version ~1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.