Strong tests, release notes, and security tooling improve day-to-day confidence. The small two-person contributor base and missing security policy leave limited resilience.
68%
Total Score
67
94
75
The repository is owned by an individual account rather than an organization, so the concentrated contributor activity has no visible organizational handoff cushion.
This is the package's first registry release, published less than one day ago, so there is no demonstrated release track record yet.
Two contributors are active, but one accounts for about 79% of recent commits, leaving meaningful concentration risk for a user-owned project.
The repository has no security policy, which leaves vulnerability reporting and response expectations unclear.
All four workflows were analyzed cleanly and all 28 action references are pinned, but two high-confidence findings report floating latest container images in mftf.yml; this is a workflow hygiene and reproducibility concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twilio/sdk Version ^8.0 | — | — |
magento/framework Version ^103.0.8 | — | — |
magento/module-eav Version ^102.1.8 | — | — |
magento/module-email Version ^101.1.8 | — | — |
magento/module-quote Version ^101.2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.