The repository remains available under an organization, with a clear README, stable versioning, and an explicit license. However, this security module has had no release for more than eight years and no commits for nearly six years; pin this version only if its Magento compatibility is already validated.
46%
Total Score
50
75
50
The latest release was published more than eight years ago, and there have been no releases in the last 12 months. Although 38 releases show substantial historical activity, the current gap is a serious abandonment concern.
There were zero commits and zero active maintainers during the last three months. Combined with the old latest release, this strongly increases abandonment risk.
There were no new or closed issues or pull requests in the last month, with two issues still open. This is consistent with a project receiving little current attention.
The repository uses Composer, but no security-scanning tools were detected. For a security-focused Magento module, that weakens maintenance transparency, though it is not severe on its own.
The linked repository is not archived, which preserves a path for maintenance, but its last push was nearly six years ago and therefore does not demonstrate active support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
endroid/qrcode Version ^2.5 | — | — |
spomky-labs/otphp Version ~8.3 | — | — |
yubico/u2flib-server Version ^1.0 | — | — |
christian-riesen/base32 Version ^1.3 | — | — |
donatj/phpuseragentparser Version ~0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.