Usable with caveats: it has a clear MIT license, focused dependencies, documentation, and an active-looking unarchived repository. However, this is a brand-new one-release package with no observed commit activity, no security scanning, and no security policy, so its long-term maintenance is unproven.
65%
Total Score
75
100
78
88
This is the first release, published less than 1 hour ago, so there is no release history demonstrating sustained maintenance or compatibility follow-up.
The repository has recorded 0 commits and 0 active maintainers in the last 3 months. Because the repository and package are newly published, this is not proof of abandonment, but it leaves maintenance capacity unverified.
The repository has 0 stars, 1 fork, and 0 watchers. Low popularity is only supporting evidence and does not outweigh the package's focused documentation, but it offers no independent maturity signal.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning reduces transparency around automated security hygiene without making the package unfit on its own.
The repository has no security policy. For a Magento extension that runs inside a commerce application, the absence of a documented vulnerability-reporting process is a genuine transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.4 <104 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.