The module is narrowly scoped, licensed clearly, and includes a README plus release notes for this version. Check compatibility with your Magento version before pinning it.
57%
Total Score
50
83
50
The package has had four releases, but none in roughly three years; its latest release was published in July 2023. This materially raises abandonment risk despite the established 1.0.x line.
The repository recorded no commits and no active maintainers in the past three months, consistent with the long release gap. That weakens evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. This makes package-to-source ownership less transparent, even though the repository contents are small and plausible for the module.
The repository has no security policy. For a small Magento extension this is a modest transparency gap, not evidence that the release is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-eav Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-catalog-import-export Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.