The package includes a clear README, changelog, release notes, and MIT declaration. Its one-person ownership, no recent commits, absent security policy, and repository naming mismatch leave maintenance and provenance concerns.
55%
Total Score
50
100
78
75
Only one registry account has publish access. The short list is more concerning here because the repository is user-owned and recent commit activity shows no active maintainer base.
Only two releases have appeared, both within roughly two days, and no later release activity is shown over the package's 155-day age. This is limited evidence of an established maintenance pattern.
There were zero commits and zero active maintainers in the last three months. For a package only about five months old, that is a meaningful maintenance concern.
The repository name does not match the package name and its README does not mention this package. That raises a concrete concern that the linked source may not clearly belong to the published package.
The repository has zero stars, zero watchers, and one fork. Popularity is only supporting evidence, but these counters provide little external evidence of project maturity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.