The package has clear documentation, tests, release notes, an MIT license, and organization backing. Its small repository has limited security tooling, so maintenance and review capacity should be watched.
67%
Total Score
88
100
88
50
The package has existed since May 2020 with 13 releases, but its latest release was about 17 months ago and it had no releases in the last 12 months, which lowers confidence in current maintenance.
There were no commits and no active maintainers in the last 3 months, reinforcing the long release gap and creating a real concern about current maintenance capacity.
Composer build tooling is present, but no security scanning tools are configured, leaving a modest repository hygiene gap for a package that integrates into Magento applications.
The repository has no security policy, which makes vulnerability reporting less transparent, although this is a moderate documentation gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-store Version * | — | — |
magento/module-config Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-checkout Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.