Usable with caveats: the package is clearly documented, tested, licensed, and not deprecated, but it is a new release with only one recent commit from one contributor. Its low adoption and lack of a security policy leave limited evidence of long-term maintenance.
68%
Total Score
63
100
83
90
The repository is owned by the same individual namespace as the package and is not organization-backed, so the single-maintainer concerns are not offset by visible organizational backing.
This is a very new package with one release over the last 50 days, so there is little release history to demonstrate sustained maintenance.
All recent commits come from one contributor, creating a concentrated maintenance dependency and increasing continuity risk for this user-owned project.
Only one commit was recorded in the last three months, all from one active maintainer, leaving limited evidence of sustained development.
The repository has zero stars and one fork, offering little community validation; this is a supporting concern rather than decisive evidence for a small, specialized package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-ui Version * | — | — |
magento/module-eav Version * | — | — |
magento/module-rule Version * | — | — |
magento/module-store Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.