The package has a steady release cadence, a clear license, release notes, and an active organizational repository. It also includes a security policy and avoids install-time scripts.
72%
Total Score
83
100
83
All 9 recent commits came from one contributor, giving the project a narrow recent contributor base. Organizational ownership partly compensates because maintenance can be handed off within the organization, but the concentration still warrants caution.
All five workflows were analyzed successfully, but all six action references are unpinned and four high-confidence findings report unpinned or floating container images. These workflow reproducibility and supply-chain hygiene gaps lower confidence in the build process, even though no untrusted checkout or script-injection path was found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
loki/magento2-css-utils Version ^1.0 | — | — |
loki/magento2-components Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.