The package has clear consumer documentation, matching license metadata, and a recorded release note. Maintenance currently depends on one contributor, while the repository has no security policy or scanning; its organization backing partly offsets the bus-factor risk.
70%
Total Score
75
100
83
83
One contributor made all eight commits in the last three months, creating a meaningful maintenance continuity risk. Organization ownership provides some ability to hand work off, but no second active contributor is shown.
Eight commits in the last three months show ongoing work, but the activity is concentrated in a very small contributor base.
The repository name matches the package, reducing identity concern, but its README does not mention the package name. That leaves a modest transparency gap about the package-to-repository relationship.
The repository has no stars and one fork. For a package only about 103 days old, this is weak supporting evidence but does not outweigh its recent releases and active commits.
Composer build tooling is present, but no security scanning tools were detected. That reduces automated oversight for a package intended to alter application request handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
opengento/module-application Version 0.11.2 | — | — |
magento/module-two-factor-auth Version * | — | — |
opengento/magento2-frankenphp-base Version ^0.9.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.