It has a matching repository, a clear license, and no install-time scripts. Organization ownership and a stable version provide some continuity, but security tooling is absent.
52%
Total Score
67
81
75
This package has only one release, published about 18 months ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance.
There were no commits and no active maintainers in the last three months. Combined with the single-release history, this is meaningful evidence of limited recent maintenance.
Five issues remain open, with no new or closed issues and no merged pull requests in the last month. This suggests little recent project activity, though it is not evidence of abandonment by itself.
Composer build tooling is present, but no security scanning tools were detected. That weakens release oversight and transparency.
The linked repository is not archived, although its last push was about 18 months ago, which reinforces the maintenance concern rather than indicating formal abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
openmage-strict/module-cms Version ^120.2 | — | — |
openmage-strict/module-eav Version ^120.2 | — | — |
openmage-strict/module-index Version ^120.2 | — | — |
openmage-strict/module-dataflow Version ^120.2 | — | — |
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.