Its small scope and straightforward Composer dependency keep adoption simple. The source is licensed and actively maintained, but no security policy or automated security scanning leaves a transparency gap.
82%
Total Score
67
100
94
75
The repository is owned by a user account rather than an organization, so there is no organization-level handoff signal. However, two contributors were active recently, providing some practical continuity.
Two contributors were active in the last three months, but the leading contributor made about 71% of commits. The second active contributor partly compensates for the concentration, leaving only a modest continuity concern.
Composer is used for the build, but no security-scanning tool was detected. That is a transparency and maintenance-process gap, though it is not evidence of unsafe code by itself.
The repository has no security policy. For an admin-facing Magento module with controllers and ACL configuration, the missing disclosure and response process is a genuine transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magepsycho/magento2-profiler Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.