The release is backed by a long-lived organization-owned project with tests, a matching license, and a recent stable release. Recent repository activity is quiet, and the project lacks a security policy and automated security scanning.
67%
Total Score
75
100
88
50
The package contains tests, and the repository also has tests. The absent README and changelog are minor transparency gaps for a Magento extension, but the test suite partly compensates for the missing project documentation.
There were no commits and no active maintainers in the last three months. This is concerning for maintenance capacity, although the recent registry release shows the project was updated at the start of that period.
Composer build tooling is present, but no security scanning tools were detected. That leaves a meaningful supply-chain oversight gap for a package integrated into a shop backend.
The repository has no published security policy, so there is no documented path for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
siel/acumulus Version ^8.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.