The package is small, clearly licensed, and backed by a matching organization-owned repository. Its minimal security tooling and absent security policy leave useful transparency gaps.
63%
Total Score
75
67
50
This is the only release, published 149 days ago, so there is limited evidence of a sustained release process. The stable 1.0.0 version avoids prerelease risk but does not offset the thin history.
The repository recorded 0 commits and 0 active maintainers in the past 3 months, which weakens evidence of ongoing maintenance. The package is only 149 days old, so this is a concern rather than proof of abandonment.
Composer is used for the build, which is appropriate, but no security-scanning tools are configured. The build tooling is a positive while the missing scanning coverage modestly lowers confidence.
The repository has no security policy, leaving no documented route for reporting vulnerabilities or explaining security handling. This is a transparency gap, not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ~101.0.0|~102.0.0|~103.0.0 | — | — |
infrangible/m2-foundation Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.