This module allows you to easily configure custom log files
64%
Total Score
75
88
50
The package runs post-install and post-update Composer scripts, increasing the work performed automatically during dependency changes. No other provided signal shows those scripts are unsafe, so this is a review concern rather than a severe risk.
Only four releases have been published since June 2020, with no releases in the last 12 months and a median interval of about 21 months. This indicates slow maintenance, though the latest release is recent enough to show the project is not abandoned.
The repository had zero commits and zero active maintainers in the last three months. That is a meaningful maintenance concern for a dependency, despite the recent 5.0.0 release.
The only workflow was fully analyzed and has no untrusted checkout or injection findings, but both action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own but leaves the unpinned actions as a hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^100.1.7|^101.0.1|^102.0|^103.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.