The repository is active enough to remain available and clearly matches the package, with a documented 0.12.2 release and a small runtime dependency set. However, registry releases stopped over two years ago, recent commit activity is absent, and no security policy is published.
62%
Total Score
75
100
79
83
The package has 46 releases and a median interval of about 12 days, but its latest registry release was over two years ago and there were no releases in the last 12 months. This is a meaningful maintenance concern.
There were no commits and no active maintainers in the last three months. The unarchived repository is a compensating signal, but it does not remove the concern about current maintenance.
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanning coverage is a modest transparency and hygiene gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it is not by itself evidence that the package is unsafe.
Version 0.12.2 is not a prerelease, but the package remains below major version 1.0. That signals some maturity risk, partly offset by its long release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-cms Version 103.*|104.* | — | — |
symfony/http-client Version ^5.4 | — | — |
mooore/magento2-module-wordpress-integration Version ^0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.