Clear licensing, documentation, and project ownership make the package easy to assess. Its same-day release history and no observed recent commit activity leave maintenance maturity unproven, while no security policy adds a smaller transparency gap.
68%
Total Score
75
100
88
83
All 15 releases were published on the same day, so there is not yet enough history to demonstrate sustained maintenance or a stable release cadence.
No commits or active maintainers were observed in the last three months. Because the package is newly published, this is mainly an unproven-maintenance concern rather than evidence of abandonment.
There were no new or merged pull requests in the observed month, and issue counts are partly unknown; this provides little evidence of an active maintenance process.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency for vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-catalog Version ^104.0 | — | — |
magento/module-graph-ql Version ^100.4 | — | — |
magento/module-url-rewrite Version ^102.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.