The package is well documented, licensed, stable, and clearly tied to its Mageplaza repository. The main concern is that no registry release or repository commit activity was recorded in the last 12 months and no security policy is present.
69%
Total Score
75
100
88
83
The package has existed since 2017 with 23 releases and a typical historical interval of about 43 days, but it has had no registry release in the last 12 months. This indicates a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete sign of currently limited development activity, partially offset by the recent repository push timestamp.
The repository uses Composer build tooling, appropriate for this package, but no security scanning tools were detected. The missing scanner is a modest transparency and hygiene gap.
No security policy was found in the linked repository. For a Magento extension that runs in an ecommerce application, this weakens the project's vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mageplaza/module-core Version ^1.5.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.