The repository includes a clear README, changelog, and matching package source, with organization backing. Composer is the only build tooling and no security scanner is present, while the project has no observed activity beyond its first release.
66%
Total Score
75
86
75
The package was published today and has only one release, so there is not yet enough release history to demonstrate sustained maintenance. Its newness partly explains the limited evidence but does not remove the adoption risk.
There were no commits or active maintainers in the past three months. Because the package itself is newly published today, this is partly expected, but it leaves maintenance capacity unproven.
The repository uses Composer, matching the package ecosystem, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
No repository security policy was found. For a small Magento extension this is a transparency gap, but it is not severe on its own.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-config Version ^101.2 | — | — |
magento/module-backend Version ^102.0 | — | — |
magento/module-catalog Version ^104.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.