The organization-backed repository is intact, documented, and has a release note for this version, but maintenance has stopped since June 2025 and the license metadata conflicts with the bundled GPL-3.0 file. Pin 1.0.2 and confirm the intended license before adoption.
55%
Total Score
75
83
75
A license file is present, so this is not an unlicensed release, but it was detected as GPL-3.0 while the manifest declares MIT. That unresolved mismatch creates a real adoption and compliance concern.
The package has only three releases and none in the last 12 months; its latest release was roughly 15 months ago. This indicates a small, currently inactive release cadence, though the package is still relatively young.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. The non-archived, organization-backed repository provides some continuity but does not offset the absence of recent activity.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both referenced actions are unpinned. The missing top-level permissions block is acceptable on its own and does not add material risk here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-catalog Version ^104.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.