The project has gone about four months without a commit, and only one release was published in the last year. Its repository is active and correctly identified, but all three workflow actions are unpinned and no security policy is provided.
65%
Total Score
75
92
67
The package is mature, with releases since 2019, but only one release appeared in the last 12 months; that slower cadence lowers confidence in ongoing maintenance.
The repository recorded no commits and no active maintainers in the past three months, which is a meaningful maintenance concern for a payment module.
The linked organization repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a payment-related component.
The only workflow was fully analyzed and had no dangerous findings, but all 3 of its action references are unpinned, leaving build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mygento/module-base Version ~2.4.0 | — | — |
magento/module-payment Version 100.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.