A Magento 2 module that modifies the built-in GraphQlCache FPC.
78%
Total Score
88
100
94
67
Post-install and post-update Composer scripts execute during dependency operations, adding operational complexity and a larger installation surface than a package without lifecycle hooks.
One contributor made all eight commits in the last three months, creating a concentrated maintenance dependency even though the repository is organization-owned.
No repository security policy was found, leaving vulnerability reporting guidance undocumented; this is a transparency gap rather than evidence of unsafe code.
Version 0.0.5 is not a prerelease, but the package remains below a stable 1.0 major version, so its public API may still change.
All three workflows were analyzed without findings, and no untrusted checkout or script injection was detected. However, all three action references are unpinned, weakening build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102.0 || ^103.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.