The repository has no commits or active maintainers in the last three months, and it has only three stars. There is no security scanning or policy, although licensing, documentation, release notes, and packaging are in place.
60%
Total Score
50
100
81
75
The source repository is owned by an individual account rather than an organization, so the single registry maintainer provides limited visible backing for continued support.
The package has made no releases in the last 12 months, despite being only about 15 months old, which points to limited ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may have stalled.
The repository has only 3 stars, 1 fork, and 2 watchers, providing little evidence of broad community review or support. Low popularity is supporting evidence rather than a decisive defect.
Composer build tooling is present, but no security scanning tools are configured, leaving a meaningful transparency and maintenance gap for a Magento integration module.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 103.0.8 | — | — |
mage-stack/module-core Version 1.0.2 | — | — |
mage-stack/module-opensearch Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.