The repository is small and has no security policy, while release notes and organization backing add useful context. The license file says MIT despite a proprietary manifest declaration, so verify the intended licensing before adoption.
67%
Total Score
100
100
78
83
The artifact contains an MIT license file and the repository also has a license file, but the manifest declares Proprietary. This mismatch should be resolved before adoption.
The package has only two releases, both within its first year, with the latest release on October 20, 2025. This provides limited evidence of a sustained release cadence.
The repository has zero stars and watchers and one fork, so there is little public usage evidence. Popularity is supporting evidence only, and the organization backing partly offsets this weakness.
Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
select-co/module-core Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.