It has a clear README, MIT licensing, and release notes, but the package is explicitly not fully tested. Its narrow patch scope may limit exposure, though adopting it should include compatibility testing against the target Magento versions.
47%
Total Score
0
60
50
The package has only two releases, both published in April 2024, and no releases in the following 12 months. This leaves compatibility and maintenance uncertain for a package that changes Magento installation behavior.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has seen no observed development since April 2024.
Composer build tooling is present, but no security-scanning tool was detected. That reduces automated supply-chain hygiene evidence without proving a defect in the package.
The linked repository has no security policy, leaving the process for reporting and handling vulnerabilities unclear. This is a transparency gap, though it is less significant for a very small patch package.
Version v0.1.1 is not a stable-major release, so the API and patch behavior may still change. The absence of prerelease labeling is mildly reassuring but does not offset the early maturity level.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.