The package is licensed, documented, and has a matching organization-backed repository. Its dependency set is broad for a Magento module, while security and longer-term maintenance evidence are limited.
62%
Total Score
75
50
88
75
The module declares 16 runtime dependencies, including many Magento components; this is substantial but broadly consistent with a Magento wishlist GraphQL integration, so it is a modest complexity concern rather than a severe risk.
All 27 releases were published within the same day and the package age is 0 days, so there is not yet meaningful evidence of sustained release maintenance.
The repository shows 0 commits and 0 active maintainers over the last three months. Because the package is newly published, this may reflect its short history, but it leaves maintenance capacity un demonstrated.
Composer build tooling is present, but no security-scanning tools are reported. This is a hygiene gap that lowers transparency without independently making the release unfit.
The repository has no security policy, leaving vulnerability-reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^103.0 | — | — |
selveq/performance Version ^2.0 | — | — |
magento/module-quote Version ^101.2 | — | — |
magento/module-store Version ^101.1 | — | — |
magento/module-bundle Version ^101.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.