Its license files, README, changelog, and regular releases provide useful project context. Security scanning and a security policy are absent, while repository work is concentrated in one contributor.
64%
Total Score
67
94
75
One contributor made all 2 commits in the last 3 months. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
The repository has only 2 commits in the last 3 months. That is recent activity, but the small volume provides limited evidence of sustained maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. For a Magento extension, this is a meaningful supply-chain hygiene gap.
The repository has no security policy. This weakens the project's published process for receiving and disclosing vulnerabilities, though it does not by itself show abandonment.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-ui Version ^101.2 | — | — |
magento/module-cms Version ^104.0 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-config Version ^101.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.