The nine-file module is documented and has a stable 1.1.0 release with no install-time scripts. However, it is newly published, has had no commits or active maintainers for three months, and provides no security policy or scanning.
60%
Total Score
50
100
88
88
The package is only 146 days old and has two releases clustered within a short period, so there is limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers during the past three months. This is a meaningful maintenance warning, although the package is still relatively new.
Composer is used for the build, but no repository security-scanning tool was detected. For a small module this is a hygiene gap rather than evidence of abandonment on its own.
The linked repository has no security policy, reducing transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0 | — | — |
magento/module-config Version * | — | — |
magento/module-customer Version * | — | — |
jeanmarcos/module-core-local-development Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.