Usable with caveats: the package is clearly licensed, documented, and backed by a matching repository, but it is a brand-new release with no demonstrated maintenance history and only one registry maintainer.
68%
Total Score
50
100
86
75
Only one account has registry publishing access, which creates limited publishing redundancy. The matching source repository and explicit project backing provide some compensation, but do not establish a broader maintainer base.
This is the first release, published today, so there is no track record showing sustained maintenance or compatibility over time.
The repository has no commits from active maintainers in the last three months, but the package and repository were created today, so this is primarily an unproven-history concern rather than evidence of a collapsed project.
Composer is used for the build, but no security-scanning tooling is configured, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing clarity about vulnerability reporting and response for a package intended to run inside Magento.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.4 <104 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.