Usable with caveats: the release is licensed, clearly documented, non-deprecated, and backed by a matching repository. It is brand new with no demonstrated commit history, no security policy or scanning, and almost no adoption evidence, so maintenance maturity is unproven.
65%
Total Score
67
100
78
90
The registry namespace and repository owner both identify SISL-source, and the repository is user-owned rather than organization-owned. This still provides a consistent ownership link, though limited organizational backing.
The package is only hours old and has two releases, so there is not yet enough history to demonstrate sustained maintenance or reliable release cadence.
The repository records zero commits and zero active maintainers in the last three months. Because the repository was just created, this mainly means maintenance capacity is unproven rather than that activity has collapsed.
The repository has zero stars and watchers and only one fork, indicating no meaningful adoption evidence yet; this is a maturity concern but not decisive for a newly published package.
Composer is used as the build tool, but no security scanning tools are configured, leaving vulnerability-detection practices un demonstrated.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.4 <104 | — | — |
sisl-source/magento2-msp-common Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.