Usable with caveats: it is a well-documented, tested, licensed module from an organization-backed repository, but it is very new and has only one release with just two commits from one contributor. Verify that MageDevGroup will maintain it before making it a long-term dependency.
68%
Total Score
67
100
81
88
The package is only 59 days old and has a single release, so there is little release history to demonstrate sustained maintenance or compatibility practices.
All two recent commits came from one contributor, creating a concentrated maintenance risk; organization ownership provides some ability to hand work to others but does not show that this has happened.
Only two commits were recorded in the last three months, with one active maintainer, so maintenance activity is currently thin for a new package.
Composer is used as the build tool, but no security scanning tools are present, leaving repository-level security hygiene less transparent.
The repository has no SECURITY.md policy, which makes the process for reporting and handling vulnerabilities unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0 | — | — |
magento/module-eav Version >=102.0 | — | — |
magento/module-store Version >=101.0 | — | — |
magento/module-search Version >=101.0 | — | — |
magento/module-catalog Version >=104.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.