This release is usable but relatively immature. It is licensed, non-deprecated, stable-major, backed by a matching non-archived repository that was pushed very recently, and includes a README, changelog, SECURITY.md, and a small dependency surface. However, the package is only 44 days old with three releases, has no tests, only one recent commit from one contributor, no security-scanning tooling, and no observed issue-resolution activity. The repository and package appear coherent, but the limited maintenance history and concentrated bus factor warrant caution before making it a critical dependency.
68%
Total Score
50
100
83
100
Only one registry publishing account is listed. This is a limited publishing base, although the repository evidence indicates the same project identity is actively publishing.
A substantial README and changelog are present, but neither the artifact nor repository contains tests; this leaves an unverified maintenance and regression-safety gap for a Magento module.
The repository is owned by a user account rather than an organization, so the single-contributor maintenance concentration is not mitigated by explicit organization backing.
The package is only 44 days old and has three releases, with a median interval of about 22 days; this shows some release activity but provides limited evidence of long-term maturity.
All recent commits come from a single contributor, creating a concentrated bus factor with no provided evidence of another active maintainer.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0 <104 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.