The package has clear documentation, a matching repository, and organization backing. Its MIT manifest conflicts with the repository's OSL-3.0 license, so verify licensing before adoption.
58%
Total Score
75
100
79
75
The manifest declares MIT and a license file exists, but the repository license was detected as OSL-3.0. That mismatch creates a real licensing clarification requirement.
Only three releases exist, with no release in the last 12 months and the latest published in April 2025. This indicates a meaningful maintenance slowdown, though the package is still relatively young.
There were no commits and no active maintainers in the last 3 months. This weakens confidence in ongoing maintenance, although the recent repository push shows it has not been abandoned outright.
Composer build tooling is present, but no security-scanning tooling was detected. That is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy. This reduces transparency for reporting vulnerabilities but is not, on its own, evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
qoliber/m2-datapatchcreator Version * | — | — |
markshust/magento2-module-simpledata Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.