The package is well documented, tested, licensed, and has clear release notes for this version. Organization backing and a matching repository support ownership, though its longer-term maintenance record is still short.
78%
Total Score
67
94
75
All recent commits came from one contributor. Organization backing reduces the risk compared with an unaffiliated individual project, but no second active contributor is shown.
Only one commit was recorded in the last three months, indicating limited recent development activity; the package's young age makes this less concerning but does not establish durable maintenance.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.0 | — | — |
pronko/magento2-core Version ^1.0 | — | — |
magento/module-backend Version >=102.0.0 | — | — |
magento/module-cache-invalidate Version >=100.0.0 | — | — |
magento/module-admin-notification Version >=100.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.