This release appears healthy and suitable to depend on: it has a stable release line, frequent recent publishing, an active non-archived organization-backed repository, five active contributors in the last three months, tests, a changelog, a license file, and no install-time lifecycle scripts. The main reservations are the absence of a security policy and security scanning, plus a GitHub Actions workflow using pull_request_target and an untrusted checkout without explicitly declared top-level permissions; these are repository security-hygiene concerns rather than evidence of package abandonment. The dependency set is moderately broad because the module integrates several translation providers, but it is coherent with the package's documented purpose.
88%
Total Score
100
100
94
70
The sole analyzed workflow uses pull_request_target together with an untrusted checkout, a potentially risky CI configuration even though no script injection was detected.
Composer build tooling is present, but no repository security-scanning tools were detected. The missing security tooling is a hygiene gap, though it is partly weighed against the separate workflow and package-quality evidence.
No SECURITY.md or equivalent security policy was detected, leaving vulnerability-reporting and response expectations undocumented.
The workflow has no top-level permissions declaration and does not declare read-only permissions, which weakens least-privilege clarity even though no top-level write permissions were observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9 | — | — |
magento/framework Version * | — | — |
openai-php/client Version ^0 | — | — |
deeplcom/deepl-php Version ^1 | — | — |
magento/module-catalog Version ^104.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.