The codebase is young, with most recent releases still prereleases, and 87% of recent commits come from one contributor. It has active recent work, a clear README, a GitHub release for this version, and a clean workflow audit, but the README says standalone Magento use is not yet proven.
68%
Total Score
75
79
83
The package is only 61 days old but has 5 releases in the last 12 months, showing active early development rather than abandonment; the short history limits maturity evidence.
Two contributors were active, but one accounts for 87% of recent commits, leaving maintenance highly concentrated.
Composer is used for builds, which fits the package ecosystem, but no security-scanning tooling was detected, leaving a modest transparency gap.
The repository has no security policy, so there is no documented channel or process for handling vulnerability reports.
v1.0.0 is a stable major release, but 80% of recent releases were prereleases, indicating the project is still settling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
magento/module-checkout Version >=100.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.