Its small audience and absent security policy leave less outside validation. Recent releases and a matching organization-owned repository help, but no commits in the last three months and unpinned workflow actions warrant caution.
67%
Total Score
75
100
88
75
The repository recorded no commits and no active maintainers in the last three months, a meaningful sign of recently stalled maintenance despite the recent release.
The repository has only 4 stars and 4 forks, so external adoption and review are limited; this is supporting evidence rather than a standalone health failure.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no security policy, so its vulnerability reporting and response process is not documented.
The single workflow was fully analyzed with no auditor findings or dangerous triggers, but all 3 action references are unpinned; the missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mygento/module-base Version ~2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.