The module is small and recently released, with organization ownership and a matching nine-file source tree. Its limited documentation and lack of security policy leave less context for long-term maintenance.
62%
Total Score
67
100
75
75
No license declaration, license file, or repository license file was detected, leaving the terms for using and redistributing this package unclear.
The package has existed for about 4 years and 11 months with five releases, including one in the last 12 months; the roughly annual cadence suggests limited but ongoing maintenance.
All recent commits came from one contributor, creating a concentrated maintenance dependency; organization ownership provides some handoff capacity but no second recent contributor is shown.
There was one commit in the last 3 months from one active maintainer, showing recent attention but only limited maintenance activity.
The repository name does not exactly match the package name and its README does not mention the package, so the package-to-repository relationship is less transparent despite the repository's clearly related module name.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.