Unfit to use for a new dependency: the package is marked abandoned and its source repository is archived. It has good documentation, tests, licensing, and organizational backing, but no releases in over four years and no recent commits make maintenance and compatibility a serious liability.
18%
Total Score
50
100
50
75
Packagist marks the entire package as abandoned, with no replacement specified. A package-level withdrawal is a severe adoption risk even though the release itself is not separately withdrawn.
The package has 14 releases but none in the last 12 months; its latest registry release was over four years ago. This strongly raises compatibility and abandonment concerns for a Magento extension.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms the absence of current maintenance rather than merely a slow release cadence.
The linked Mageplaza repository is archived, showing that the source is no longer actively maintained. Its last push was over three years ago, with no evidence here of ongoing support.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap, though the archived and abandoned status is more decisive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mageplaza/module-core Version ^1.4.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.