A clear license and substantial README improve transparency, and there are no install-time scripts or registry deprecation. The short release history, absent security policy, and lack of recent repository activity provide limited evidence of long-term support.
54%
Total Score
50
75
75
The package is only 103 days old and has two releases, both published within roughly two hours, so there is limited evidence of an established maintenance pattern.
The repository recorded zero commits and zero active maintainers over the last three months, despite the package being recently published; this weakens evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package, so ownership of the published package is not clearly established by the source repository.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
Version 0.0.2 is not a stable major release, which signals an early-stage API and greater compatibility risk for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orangecat/core Version * | — | — |
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.