Magento 2 merchandising and search engine built on ElasticSearch
58%
Total Score
caution
Usable with caveats — the package is deprecated in favor of smile/elasticsuite despite an active repository.
The package is marked abandoned at the package level and has a named replacement, smile/elasticsuite. This materially lowers confidence in adopting this package name even though the linked project remains active.
Composer build tooling is present, but no repository security-scanning tool was detected. This is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Seven workflows combine pull_request_target with untrusted checkouts, and all 35 analyzed action references are unpinned; the audit also found seven high-confidence conditions that always evaluate true and four ad hoc package installations. These are concrete CI supply-chain and workflow-hygiene concerns, although no script-injection findings were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=103.0.6 | — | — |
magento/module-store Version >=101.1.6 | — | — |
magento/module-backend Version >=102.0.6 | — | — |
magento/module-catalog Version >=104.0.6 | — | — |
magento/module-catalog-search Version >=102.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.