There is no security policy or automated security scanning, and the repository has only eight stars. The package is licensed and includes a usable README, but its Magento 2.2/2.3 requirement is dated.
43%
Total Score
50
67
50
The latest release was published in February 2019, with no releases in the last 12 months and only two releases overall. This long period without updates is strong evidence of abandonment risk.
Ten issues remain open, with no new or closed issues and no pull-request activity in the last month. Combined with the old repository activity, this suggests limited ongoing maintenance.
Composer is used for builds, but no security-scanning tooling is present. The established build tooling helps reproducibility, while the missing scanning reduces maintenance assurance.
The repository is not archived, which is a modest positive, but it was last pushed in May 2019 and therefore does not offset the long release gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency and maintenance gap for an extension integrated into Magento stores.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-catalog Version * | — | — |
magento/module-layered-navigation Version * | — | — |
shopigo/magento2-extension-ajax-listing Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.