Its small Composer dependency surface and organization ownership keep integration straightforward. The repository includes release notes and a changelog, but has no tests or security scanning. Pin this version if adopting it in production.
60%
Total Score
75
100
79
50
The artifact contains an MIT license file, but the manifest declares the package as Proprietary. That mismatch creates avoidable licensing ambiguity for consumers.
The package has only two releases, both published on the same day, and no release has appeared for about 11 months. This provides limited evidence of an established maintenance cadence.
There were no commits and no active maintainers during the past three months, following the last push about 11 months ago. That is meaningful evidence of weak current maintenance.
The repository uses Composer, but no security scanning tools were detected. For a small package this is a hygiene gap rather than a standalone dependency blocker.
The repository has no security policy. This reduces transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.