The package includes a clear README, changelog, license files, and a stable release pattern. Repository security documentation and scanning are absent, so maintenance oversight is limited.
68%
Total Score
67
100
89
75
One contributor accounts for all recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown to share current maintenance responsibility.
The repository has only 4 commits in the last 3 months, all from one active maintainer. That is some recent activity, but the limited volume and concentration reduce maintenance resilience.
The repository has 0 stars, 1 fork, and 0 watchers. This indicates limited visible adoption, but popularity is supporting evidence and does not outweigh the observed release and repository activity.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning lowers assurance for a package that runs inside a Magento application.
The repository has no security policy. This does not prove a security problem, but it leaves vulnerability reporting and response expectations undocumented.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-ui Version ^101.2 | — | — |
magento/module-eav Version ^102.1 | — | — |
magento/module-sales Version ^103.0 | — | — |
magento/module-store Version ^101.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.