The stable release and matching organization-backed repository provide useful continuity. Maintenance has been quiet for nearly a year, and the workflow needs tighter dependency pinning. Its small scope and clean audit reduce, but do not remove, adoption risk.
65%
Total Score
75
90
67
The package has only 3 releases since April 2019, with a median interval of about 3 years and 4 months; one release in the last 12 months shows it is not abandoned, but cadence is sparse.
There were 0 commits and 0 active maintainers in the last 3 months, indicating limited recent development activity despite the recent release.
The repository has no security policy, which weakens vulnerability-reporting transparency, although the clean workflow audit provides some compensating project hygiene.
The workflow audit found no dangerous triggers, injection paths, or audit findings, but all 3 analyzed action references are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-deploy Version 100.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.