Documentation and packaging are thorough, with tests, a changelog, and no install-time scripts. The project is brand new, so maintenance history and security-process evidence remain limited; pin this version and reassess after subsequent releases.
68%
Total Score
67
100
88
75
Only one registry publishing account is listed, which limits visible publishing redundancy. The organization-owned repository provides some backing, so this is a modest concern rather than a severe maintainer risk.
This is the only recorded release, published less than a day ago, so there is no meaningful release track record yet. The repository and package contents provide some compensating transparency, but not evidence of sustained maintenance.
There were no commits or active maintainers in the past three months. Because the package is only hours old, this is largely an absence of history rather than proof of abandonment, but it leaves maintenance capacity unproven.
Composer is used as the build tool, but no repository security scanning tool was detected. The missing scanning is a hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is not by itself evidence of poor code maintenance.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-store Version ^101.0 | — | — |
magento/module-config Version ^101.0 | — | — |
magento/module-widget Version ^101.0 | — | — |
magento/module-backend Version ^102.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.