The package is licensed, matches its organization-backed repository, and uses no install-time scripts. Its maintenance record is thin, so pinning this version carries a meaningful abandonment risk.
55%
Total Score
67
88
75
Only one release exists, with no releases in the last 12 months and roughly 18 months since publication; this leaves little evidence of an established release cadence.
The repository recorded no commits and no active maintainers in the last three months, consistent with the roughly 18-month-old last push and raising abandonment concerns.
Five issues remain open, with no issues or pull requests opened or closed in the last month; this provides no recent evidence of active maintenance.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities, although this is a hygiene gap rather than a severe dependency risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
openmage-strict/module-cms Version ^120.2 | — | — |
openmage-strict/module-sales Version ^120.2 | — | — |
openmage-strict/module-catalog Version ^120.2 | — | — |
openmage-strict/module-customer Version ^120.2 | — | — |
magento-hackathon/magento-composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.