N/A
45%
Total Score
0
71
83
The package has had no release in more than three years, despite five releases since April 2022. That long period without a new release is a meaningful abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing no release in more than three years. This strongly limits evidence of ongoing maintenance.
The published artifact has no README, which makes a small Magento integration harder to evaluate and use. The absence of tests and a changelog in the artifact is normal packaging practice, while the GitHub release for this version is a positive documentation signal.
The repository name does not match the package name, and no README mention was collected. This creates uncertainty that the linked repository is the intended project source rather than a nearby or shared repository.
No security policy was found in the repository, leaving vulnerability reporting and maintenance expectations unclear. This is a transparency gap, though it is less significant than the observed inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-eav Version * | — | — |
magento/framework-message-queue Version * | — | — |
mateuszmesek-magento2/module-document-data Version ^1.0 | — | — |
mateuszmesek-magento2/module-document-data-api Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.