The repository is new and has no recorded commit activity beyond its initial publication. Documentation, licensing, package structure, and dependency declarations are clear, but the project has no tests or security-scanning tooling, so its maintenance track record remains unproven.
62%
Total Score
75
100
89
83
This package is less than one day old with only two releases, so there is not yet enough release history to demonstrate sustained maintenance or stability.
There were zero commits and zero active maintainers in the previous three months. Because the package was published less than one day ago, this is primarily an unproven maintenance record rather than evidence of abandonment.
Composer is used for the build, but no security-scanning tool is configured. For a new package this is a meaningful hygiene gap, though it is not evidence of unsafe behavior by itself.
The repository has no security policy, reducing the transparency of vulnerability reporting and maintainer response procedures.
No GitHub Actions workflows were present, so the audit found no workflow hazards; it also provides no automated maintenance or security checks to support confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-review Version ^100.4 | — | — |
magento/module-graph-ql Version ^100.4 | — | — |
magento/module-review-graph-ql Version ^100.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.