Clear installation guidance and a stable release history support adoption. Organization backing and a documented repository add useful context, but the project remains young and has limited operational maturity.
64%
Total Score
67
88
50
The package declares no license, contains no license file, and the repository has no license file. That leaves usage and redistribution rights unclear for a Magento integration.
One contributor made all 8 commits in the last 3 months, creating a high single-maintainer dependency. Organization ownership provides some handoff potential, but no second active contributor is shown.
The repository recorded 8 commits in the last 3 months, showing recent maintenance. All activity comes from one maintainer, so ongoing maintenance capacity is limited.
The repository uses Composer for builds, which fits the package ecosystem, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For an integration that handles orders, customers, inventory, and webhooks, the absence of a documented vulnerability-reporting process lowers operational maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
honl/magento2-import Version ^1.3 | — | — |
magento/product-community-edition Version ^2.4 | — | — |
opengento/module-category-import-export Version ^0.5.6 | — | — |
ampersand/magento2-disable-stock-reservation Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.