This is a generally usable and transparent Magento module with a stable 1.3.6 release, six releases in the last 12 months, a permissive MIT license, a linked non-archived organization-owned repository, and a small runtime dependency footprint. The main concern is maintenance evidence: the repository recorded zero commits and zero active maintainers in the last three months, while issue activity shows one new issue with none closed; the absence of tests, security scanning, and a security policy further limits assurance. The package is suitable to consider, but production adopters should verify current responsiveness and test it against their Magento version, especially because its documented purpose involves retaining potentially sensitive API request and response data.
68%
Total Score
75
100
89
90
A readable README and GitHub Releases are present, but neither the artifact nor repository contains tests or a changelog. The missing tests reduce maintenance assurance for a backend module, although the release history provides some compensating evidence.
The repository recorded zero commits and zero active maintainers over the last three months. Although recent registry releases provide partial compensation, the lack of observed development activity is a meaningful maintenance and abandonment concern.
There are only 3 open issues, but one new issue appeared in the last month with no issues or pull requests closed. This suggests limited demonstrated issue-response activity and warrants caution.
Composer is used as the build tool, but no security-scanning tools are configured. The missing scanning is a transparency and assurance gap, though it is not by itself evidence that the package is unsafe.
The repository has no security policy. For a module that processes API request and response data, this is a genuine disclosure-process gap and modestly lowers confidence in ongoing security maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-webapi Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.