The package is narrowly scoped, has a clear README, a license, and a matching source repository. Pin 1.0.0 and plan for replacement if Magento compatibility or translation fixes become important.
58%
Total Score
50
100
79
83
The repository is owned by an individual account rather than an organization, so the single registry maintainer is consistent with the available ownership context. This provides limited maintenance redundancy.
The only release was published in April 2018, with no releases in the last 12 months, indicating a long period without published updates. A stable translation package may need few changes, but this still raises maintenance uncertainty.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with an inactive project. Its narrow scope partly reduces the need for frequent changes, but does not offset the absence of recent maintenance evidence.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community review or adoption. Popularity is only supporting evidence, so this does not determine the result by itself.
Composer is used for the build, which fits the package ecosystem. No security scanning tools are present, a modest transparency gap, but this is not severe for a static translation artifact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.