Its license and release notes are clear, but the project has no security policy and only one registry maintainer. The package should not be adopted without a maintained successor or verified fork.
15%
Total Score
25
40
83
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The package has 17 releases over nearly 6 years, but none in the latest 2 years and 9 months since January 2024. The earlier cadence does not offset the prolonged release gap.
The repository recorded zero commits and zero active maintainers in the last 3 months. This confirms that active maintenance has stopped rather than merely slowed.
The linked source repository is archived, and its last push was on January 1, 2024. Archived source is a severe abandonment risk for a package still expected to support consumers.
Only one account has registry publishing access. A single maintainer can be adequate for a small project, but this package has no provided organization backing to compensate for the resulting continuity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
openmage/magento-lts Version >=19.4.0 || main-dev || next-dev | — | — |
symfony/polyfill-php80 Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.