The package has clear documentation, tests, a changelog, release notes, and a security policy. Recent repository work is sparse and concentrated in one contributor, while workflow permissions, unpinned actions, and a high-confidence template-injection finding add maintenance and release-process concerns.
64%
Total Score
50
94
83
The repository is owned by an individual rather than an organization, so the concentrated recent contribution pattern is not offset by visible organizational backing.
All recent commits came from one contributor, leaving the project dependent on a single active source contributor.
Only one commit was recorded in the last three months, indicating sparse recent maintenance despite the recent release history.
Two issues were opened in the last month while none were closed, and 14 issues remain open; this suggests unresolved maintenance demand.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version >= 1.0 | — | — |
magento/framework Version ~103.0.4 | — | — |
magento/module-ui Version ~101.2.4 | — | — |
magento/module-eav Version ~102.1.4 | — | — |
magento/module-tax Version ~100.4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.