The package has a clear README, changelog, matching repository, and no install-time scripts. Its proprietary license is explicit, but there is no security policy and the publishing base is one person.
43%
Total Score
25
79
75
This is the package's only release, published over 8 years ago, with no releases in the last 12 months. That strongly suggests abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the last push occurring in April 2019. This leaves compatibility and maintenance concerns unresolved.
Only one account has registry publishing access. The repository is user-owned rather than organization-owned, so there is little visible redundancy in the publishing base.
Composer is used for builds, which is appropriate, but no security-scanning tooling was detected. That weakens automated security hygiene without proving a vulnerability.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a secondary concern alongside the stronger maintenance signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mozgbrasil/magento-base-php_71 Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.