Healthy and reasonable to adopt, with a small-maintainer caveat. It has frequent stable releases, recent repository activity, matching source code, and clear packaging, but all recent commits come from one contributor and there are no tests or security policy.
78%
Total Score
80
100
83
90
Only one registry account, MageMe, can publish the package. That is a real continuity concern because the repository is user-owned rather than organization-backed, although repository activity shows the maintainer is currently active.
The artifact includes a README and changelog, while the absence of tests is a modest transparency gap because the repository also has no tests to compensate for it.
One contributor made all 9 commits in the last 3 months, creating a concentrated maintenance dependency with no demonstrated handoff capacity.
The repository has only 2 stars and 2 forks, which is limited adoption evidence, but popularity is supporting evidence and does not outweigh the active release and commit history.
Composer is used for builds, but no security scanning tools are present. The missing scanning is a hygiene gap, though it is not evidence that the package is unsafe or abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mageme/module-core Version ^2.0 | — | — |
mageme/module-eu-withdrawal Version ^1.1.3 | — | — |
hyva-themes/magento2-theme-module Version ^1.3.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.