The small dependency footprint, stable release, and organization ownership make the package straightforward to adopt. Its limited project tooling and sparse documentation reduce transparency for long-term maintenance.
43%
Total Score
50
100
71
50
The package has had three releases, all concentrated between November 20 and November 30, 2022, with no releases in the last 12 months. This short-lived release history is a meaningful abandonment concern.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the package's long release gap. There is no provided activity evidence showing ongoing maintenance.
The artifact has no README, tests, or changelog, while the repository also has no tests or changelog. Missing tests and changelog are normal for published artifacts, but the absent consumer-facing README and lack of repository verification reduce transparency for this integration module.
Composer is used for the build, which fits the package ecosystem, but no security scanning tooling is present. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository has no security policy. For a small Magento module this is a transparency gap, though it is less significant than the clear evidence of dormant maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
ghostunicorns/module-crt-base Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.