A stable release, clear licensing, and a small dependency set are positive. Those strengths do not offset the lack of an active project to maintain or support this dependency.
15%
Total Score
0
100
64
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a severe warning that ongoing maintenance and support may not be available.
The repository had zero commits and zero active maintainers in the last three months. The recent release provides limited compensation because current development activity is absent.
The linked source repository is archived, despite being pushed on October 10, 2025. An archived project is not an active maintenance base for a dependency.
Composer is used for builds, but no security-scanning tool is present. This is a modest project-hygiene gap rather than an independent reason to reject the release.
The repository has no security policy. This is a transparency gap, though it is secondary to the stronger abandonment evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openmage/magento-lts Version >=19.4.0 || main-dev || next-dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.