Clear documentation, a license, and a focused dependency set improve adoption confidence. The project is young, has no security policy, and its recent source activity comes from one contributor.
68%
Total Score
50
100
83
83
One registry maintainer account publishes the package, which is a modest concentration risk; the linked source owner is also a user account rather than an organization.
The repository owner is a user account rather than an organization, so the concentrated maintainer and contributor activity is not offset by visible organizational backing.
The package is only 57 days old with two releases about 25 days apart, so there is some release activity but limited history for judging long-term maintenance.
All three recent commits came from one contributor, giving the project a single-person maintenance dependency with no demonstrated handoff capacity.
The repository recorded three commits in the last three months, showing recent activity, but the volume is modest for a package providing a production storefront integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.