Usable with caveats: the package is licensed, documented, tested, correctly backed by its organization repository, and not deprecated or archived. However, its last registry release was about four years ago and the repository has had no commits or active maintainers in the last three months, so maintenance may have stalled.
62%
Total Score
67
100
89
88
The package has six releases since 2019, but its latest release was about four years ago and it had no releases in the last 12 months. This materially raises maintenance and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old registry release, this is the main abandonment concern.
There are no new or closed issues in the last month and one open pull request, providing little evidence of current review or maintenance activity.
Composer is used for the build, but no security scanning tools are configured. This is a transparency and maintenance gap, though not severe enough to make the package unfit on its own.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations. The absence is a genuine hygiene concern but is partly offset by the package's tests and organization backing.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-media-storage Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.