The package is clearly scoped, documented, and easy to identify in its matching source tree. Its long silence and license mismatch make a current Magento dependency a risky choice.
42%
Total Score
0
100
75
83
This is a single-release package first and last released on August 30, 2021, with no releases in the past year; the lack of subsequent maintenance is a substantial abandonment concern.
The repository had no commits and no active maintainers in the past three months, consistent with the last push in August 2021 and indicating that maintenance has stopped.
A license file is present, but the manifest declares OSL-3.0 and AFL-3.0 while the artifact license file was detected as BSD-2-Clause; that mismatch creates licensing uncertainty.
The repository has zero stars and forks and only two watchers, providing little evidence of external adoption or community support; this reinforces, but does not independently establish, the maintenance concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap for a package integrated into Magento sites.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=102.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.