The focused 28-file module and release notes provide useful packaging context. No security scanning, tests, or security policy are evident, and the single release has seen no repository activity for nearly four years.
42%
Total Score
25
100
61
83
This is the package’s only release, published nearly four years ago, with no releases in the past year; that limits evidence of ongoing maintenance.
There were no commits and no active maintainers in the past three months, consistent with an effectively inactive project and elevated abandonment risk.
Release notes document this exact version, but the package has no README or tests; the missing README reduces consumer guidance for a Magento integration.
The source repository is owned by an individual account rather than an organization, providing limited visible project backing for a package published under the pay namespace.
The repository name does not exactly match the package name, and no README package mention was available; this weakens confidence that the linked repository clearly identifies the published package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 100.0.*|101.0.*|102.0.*|103.0.*|104.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.