The release includes tests, a changelog, release notes, and a clear license file. Its single runtime dependency keeps integration simple, but the project’s maintenance evidence is too weak for a new dependency.
12%
Total Score
0
100
30
Packagist marks the entire package as abandoned, with no replacement named. This directly indicates that the release should not be selected for a new dependency.
The package has only 5 releases and none in the last 12 months; its latest release was about 4 years and 3 months ago. This shows that maintenance has stopped rather than merely slowed.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, reinforcing the abandonment indicated by the archived repository and stale release history.
The linked source repository is archived, and it was last pushed about 3 years and 7 months ago. An archived project is a severe abandonment risk even though the package has a clear source location.
The artifact contains an MIT license file, so licensing is documented, but the manifest declares the package as proprietary. That mismatch creates a real adoption and compliance ambiguity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mageplaza/module-core Version ^1.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.