The declared OSL-3.0 license conflicts with detected MIT license text, creating avoidable licensing uncertainty. The repository also lacks a security policy and security-scanning tools, while its organization backing is a modest positive.
38%
Total Score
100
50
50
This package has only one release, published in April 2021, with no releases in the last 12 months. That is strong evidence of an unmaintained dependency, although the repository is not archived.
The manifest declares OSL-3.0, while license files in the artifact are detected as MIT; repository license files are present but do not resolve the mismatch. This creates material licensing uncertainty for adopters.
Composer build tooling is present, but no security-scanning tools were detected. This is a moderate transparency and maintenance gap rather than evidence that the package is unsafe.
The repository is not archived, which preserves a path for future maintenance, but its last push was in May 2022. The long period without observed repository activity remains a meaningful abandonment concern.
The linked repository has no security policy. For a package that changes Content Security Policy behavior, the absence reduces transparency around vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magex/base-module Version 1.0.* | — | — |
magento/module-csp Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.