Documentation, release cadence, and organization backing provide useful support. The very small active contributor base and lack of repository security controls leave meaningful maintenance and transparency concerns.
68%
Total Score
67
94
75
One contributor made all recent commits, creating concentration risk; organization ownership provides some ability to hand maintenance off, so this is not severe on its own.
Only 2 commits were recorded in the last 3 months, indicating limited recent development activity despite the recent registry releases.
Composer is used for builds, but no security-scanning tools were detected. This reduces transparency around routine security checks.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-store Version ^101.0 | — | — |
magento/module-widget Version ^101.0 | — | — |
magento/module-catalog Version ^104.0 | — | — |
mage2kishan/module-core Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.