The package is small and focused, with a changelog, stable version, and organization-backed repository. Its lack of security policy or scanning leaves some transparency gaps, while the single release and inactive recent commit history make long-term maintenance uncertain.
62%
Total Score
75
100
83
75
Only one release exists, published about 14 months ago, with no releases in the last 12 months. This is a meaningful maintenance concern, though the package may be intentionally stable.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this leaves current maintenance capacity uncertain.
The repository has one star and one fork, providing little external adoption evidence. Popularity is only supporting evidence, so this is a modest concern rather than a decisive risk.
Composer build tooling is present, but no security-scanning tools were detected. That weakens visible security maintenance practices.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, but it is not severe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
select-co/module-core Version 1.0.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.