The MIT license, README, stable versioning, and absence of install scripts provide a solid baseline. There is no repository security policy or automated security scanning, so transparency and preventive hygiene are limited.
65%
Total Score
50
100
88
83
The repository is owned by the same user namespace as the package, so the source link is consistent. The owner is an individual account rather than an organization, offering less visible institutional backing.
The package has 11 releases over about 1 year and 5 months, but only one release in the last 12 months. That indicates a materially slower release cadence for a package that requires ongoing Magento and Hyva compatibility work.
The repository recorded zero commits and zero active maintainers during the last 3 months. Combined with only one registry release in the last year, this raises concern about current maintenance capacity.
There were no new or merged pull requests and no new or closed issues during the last month, while open pull requests are zero. This provides no recent evidence of active community or maintainer response.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a modest repository hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
algolia/algoliasearch-magento-2 Version ^3.12 | — | — |
hyva-themes/magento2-default-theme Version * | — | — |
blackbird/external-resources-loader Version ^1.0 | — | — |
hyva-themes/magento2-compat-module-fallback Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.