The declared license and small runtime dependency set provide a clear installation and legal baseline. The repository has no security policy or scanning, leaving limited evidence of ongoing project safeguards.
38%
Total Score
0
100
63
75
The latest release was published in July 2019, with no releases in the last 12 months and only two releases overall. This long period without updates is strong evidence of abandonment risk for a Magento extension.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with its last push in July 2019. No newer activity offsets the stale release history.
Composer is used for the build, which is appropriate for a Packagist package, but no security-scanning tools are present. That leaves dependency and release hygiene less independently checked.
The repository has no security policy, so consumers have no documented vulnerability-reporting path. This is a secondary transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=100.0.0 <103 | — | — |
magento/module-review Version >=100.0.0 <103 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.