Usable with caveats: the package is clearly documented, licensed, and backed by a matching repository, but it has only one release and no observed commit activity yet. The repository also lacks security scanning and a security policy, so adoption should be monitored rather than treated as mature.
62%
Total Score
50
100
75
83
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This provides ownership alignment but limited evidence of institutional backing.
This is a newly published package with one release and no established release history, so maturity and long-term maintenance cannot yet be demonstrated.
No commits and no active maintainers were observed in the last three months. Because the repository is newly published, this is an early maturity concern rather than evidence of abandonment, but ongoing activity should be verified before relying heavily on it.
There are no open issues or pull requests and no recent issue or pull-request activity. With a newly created repository this is ambiguous, but it offers no evidence of an active feedback process.
The repository has no stars, forks, or watchers. For a package released today this is not decisive, but it provides no external adoption signal yet.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.4 <104 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.