The MIT license, focused seven-file package, and absence of install scripts make it easy to inspect and integrate. The README clearly limits it to development use, but long-term maintenance evidence remains thin.
64%
Total Score
67
79
75
The package is only 67 days old and has one release, so there is not enough history to demonstrate sustained maintenance. Its recent publication partly reduces abandonment concern, but the evidence remains limited.
All recorded commits come from one contributor, so maintenance depends entirely on that individual. The repository is user-owned rather than organization-backed, so there is no provided evidence of a handoff path.
Only one commit from one active maintainer was recorded in the last three months. For a package this new, that may reflect initial development, but it provides limited evidence of maintenance capacity.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of unsafe code.
The repository has no security policy. This limits the project's documented process for receiving vulnerability reports, although the package's small, focused scope reduces the significance of that gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-email Version * | — | — |
magento/module-sales Version * | — | — |
magento/module-store Version * | — | — |
magento/module-theme Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.