The package has a clear README, changelog, license, and a small focused file tree. Its repository is not archived and its dependencies are explicit, but there is not yet enough history to establish durable maintenance.
65%
Total Score
50
100
83
50
The package was first released today and has four releases in less than a day, so there is no meaningful track record yet. This is partly offset by the focused package contents and an accompanying changelog.
The repository shows zero commits and zero active maintainers over the last three months, although it was pushed recently and the package is newly published. Maintenance capacity is therefore unproven rather than clearly abandoned.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling is present. This is a modest hygiene gap for a newly published package.
The repository has no security policy. For a small focused module this is a transparency gap, but it does not by itself indicate that the release is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-graph-ql Version ^100.4 | — | — |
magento/module-directory Version ^100.4 | — | — |
magento/module-directory-graph-ql Version ^100.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.