The README, license, and matching repository give consumers useful context and clear ownership. There is not yet enough operating history to establish dependable long-term maintenance.
58%
Total Score
75
100
86
75
The package is 0 days old, with three releases published on the same day and no established release interval. This leaves maintenance maturity unproven.
The repository recorded zero commits and zero active maintainers in the last three months. Because the package is newly published, this is partly explained by its age, but it still provides no evidence of sustained maintenance.
Composer is used as the build tool, but no security scanning tooling is present. This is a modest transparency and hygiene gap, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified for a package that integrates with Magento storefront functionality.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-catalog Version ^104.0 | — | — |
magento/module-graph-ql Version ^100.4 | — | — |
magento/module-product-alert Version ^100.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.