The package has a small dependency surface, a README, and a repository that still receives occasional updates. Its registry release history is stale, activity is concentrated in one contributor, and no license was detected.
60%
Total Score
50
100
81
75
No license declaration or license file was detected in the package or repository, leaving the terms for using and redistributing this code unclear.
The package has had no registry releases in more than six years, despite four releases overall. This is a meaningful abandonment or compatibility risk, although recent repository activity provides some compensation.
One contributor made all two commits in the last three months, so maintenance depends entirely on a single active contributor. The repository owner identity provides no demonstrated second contributor to offset that concentration.
The repository recorded two commits in the last three months, showing some current maintenance. The low volume still supports only occasional rather than active maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magefan/module-community Version >=2.0.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.