The MIT license, stable version, and lack of install-time scripts provide a clean baseline. Its minimal documentation and absence of recent project activity leave maintenance and integration risks for adopters.
52%
Total Score
50
75
83
The package has no README, tests, or changelog, which limits consumer guidance and verification; the exact version does have a GitHub release, partially compensating for the missing changelog.
The package has only two releases, with the latest published in January 2023 and none in the subsequent three years, which indicates weak ongoing maintenance evidence.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the concern that maintenance has stalled.
The repository name does not exactly match the package name, and no README mention was available, so package ownership is less transparent; this is a caution rather than proof of an unrelated repository.
Composer is used as the build tool, but no security scanning tooling is present; for this small PHP module that is a transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-cms Version * | — | — |
mateuszmesek-magento2/module-document-data Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.