The module has a clear README, matching OSL-3.0 licensing, and no install scripts. Its repository does not identify the package directly, and the young project has not shown recent commit activity, so confirm ownership and maintenance plans before adopting it.
58%
Total Score
50
70
83
The package is young at 106 days and has only two releases, both published close together, so its maintenance history is still limited.
The repository recorded zero commits and zero active maintainers in the last three months; for a package only 106 days old this is an early but meaningful maintenance warning.
The repository name does not match the package name and its README does not mention the package, leaving the package-to-source relationship insufficiently explicit despite the repository containing the module files.
The repository has no security policy. This does not show a security defect, but it reduces transparency about how dependency issues are reported and handled.
Version 0.0.2 is not a stable major release, which indicates an immature compatibility baseline for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orangecat/core Version * | — | — |
magento/framework Version * | — | — |
orangecat/module-company Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.