The stable release has a clear MIT license, modest dependencies, and no install-time scripts. Maintenance has stopped for about three years, with no recent contributors, no security policy or scanning, and weak repository identification.
52%
Total Score
25
100
67
50
The package has had five releases since May 2022, but none in the last 12 months and its latest release was about three years ago, indicating likely abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with the roughly three-year release gap and materially increasing maintenance risk.
The package has no README, tests, or changelog, but the source uses GitHub releases and this is a compact Magento module; the missing tests and changelog are not inherently packaging gaps. The absent README still weakens consumer documentation.
The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to offset the thin maintenance record.
The repository name does not match the package name and the README does not confirm the package, so the source-package relationship is less clearly documented; this is a transparency concern, though subpackages can legitimately use broader repository names.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
mateuszmesek-magento2/framework-config Version ^1.0 | — | — |
mateuszmesek-magento2/module-document-data-api Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.