The package includes a clear README, tests, MIT licensing, and release notes for this version. Organization backing and read-only workflow permissions are helpful, but the project is too new to demonstrate durable maintenance, and its workflow dependencies are not pinned.
68%
Total Score
75
100
93
67
This is the first release, published 0 days ago, so there is no release history or cadence demonstrating sustained maintenance. Its newness limits maturity evidence but does not indicate abandonment by itself.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months, although the package itself was published 0 days ago; this is insufficient history rather than proof of a collapsed project.
The repository has no published security policy, reducing transparency for a package that handles store and AI-provider interactions. No other provided signal compensates for this documentation gap.
All 7 analyzed action references are unpinned, which weakens build reproducibility and update control. The workflow uses read-only permissions and has no detected untrusted checkout, script injection, or high-severity findings, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.