The package is clearly documented and licensed, with repository tests, a changelog, and no install-time scripts. Its alpha status and one-day history leave maintenance and compatibility unproven, while the workflow uses two unpinned actions and has no security policy.
62%
Total Score
50
50
79
67
Six runtime dependencies, including Magento modules and the related core package, create meaningful compatibility surface for a Magento integration, though the profile is not unusually large.
This release comes from a package only one day old with two releases and a very short median interval, so long-term maintenance and release discipline are not yet established.
No commits or active maintainers were recorded during the last three months; because the project is only one day old, this is inconclusive but leaves maintenance capacity unproven.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.4 || ^7.0 | — | — |
magento/framework Version ^103.0 | — | — |
grinet/magmi2-core Version ^0.1@alpha | — | — |
magento/module-backend Version ^102.0 | — | — |
magento/module-catalog Version ^104.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.