The package is small and clearly documented, with a matching source repository and a straightforward runtime dependency. Its only release was about 8 years ago, and the repository had no commits in the last 3 months; one maintainer and no security policy add maintenance uncertainty.
48%
Total Score
33
100
81
88
This is the package's only release, published about 8 years ago, with no releases in the last 12 months. That long period without a new release raises abandonment risk for a production dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the old release, this is strong evidence that maintenance may have stopped.
Only one registry maintainer is listed, leaving limited visible publishing redundancy for a user-owned project. This is a modest bus-factor concern when combined with the stale release history.
The registry namespace and repository owner match, and the repository is owned by an individual account. The matching ownership supports provenance, but it does not provide the resilience of organization backing.
Composer is used as a build tool, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than proof of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mozgbrasil/magento-base-php_56 Version 1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.