The package is a focused six-file language pack with no install-time scripts or runtime complexity. Its README, matching repository, stable version, and organization backing provide useful transparency, while the absent security policy leaves assurance thinner.
68%
Total Score
75
75
83
The manifest declares OSL-3.0 and AFL-3.0, while the artifact license file is detected as MIT; the repository also has a license file, but the mismatch creates licensing uncertainty.
This package is 147 days old and has only one release, so there is little release history from which to judge sustained maintenance.
The repository recorded zero commits and zero active maintainers during the last 3 months, reducing evidence of ongoing maintenance.
Composer is used for the build, but no security-scanning tools are present, providing less automated assurance for future changes.
The repository has no security policy, leaving no documented channel or process for reporting security issues; this is a modest transparency gap for a maintained dependency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
hyva-themes/magento2-hyva-checkout Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.