The source repository is not archived, has tests and a changelog, and the release includes a README. MIT licensing and organization backing help, but zero recent commits and an unclear package-to-repository link add adoption risk.
38%
Total Score
75
58
50
Packagist marks the entire package as abandoned and names opengento/module-hoodoor as a replacement, which is a major dependency risk even though the source repository remains available.
The package has had no release in more than two years: its latest release was April 2024, with no releases in the last 12 months. This strongly suggests registry-level abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, indicating no recent maintenance capacity despite its non-archived status.
The linked repository name does not match the package name and its README does not mention this package, so the ownership relationship is not clearly established by the collected evidence.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a package that handles passwordless authentication.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.