Clear documentation and a tested release make integration easier. The project has no security policy or automated security scanning, so governance is less transparent.
84%
Total Score
100
100
94
83
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest governance gap, not evidence that the release is unsafe on its own.
The repository has no security policy. For an extension handling social-login integrations and customer accounts, that reduces transparency about vulnerability reporting and response.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10273 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. mageplaza/magento-2-social-login is vulnerable to Cross-site Scripting (XSS) in versions 4.0.0 - 4.1.17. | 4.0.0 - 4.1.17 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
hybridauth/hybridauth Version ^3.13 | — | — |
mageplaza/module-core Version ^1.5.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.