The project is backed by an organization, includes release notes and a repository changelog, and uses Composer security scanning. Maintenance has stopped for more than two years, while all three workflow actions are unpinned and the repository does not clearly mention the package.
58%
Total Score
50
100
86
75
The repository recorded zero commits and zero active maintainers in the last three months; together with the March 2024 last push, this is strong evidence of prolonged inactivity.
The package has 20 releases over more than seven years, but none in the last 12 months and its latest release was in March 2024. This shows a mature history but a substantial current-maintenance gap.
There are 14 open issues but no new or closed issues and no pull requests in the last month, consistent with an inactive project.
The repository name does not match the package name and its README does not mention the package. Although naming differences can occur for Magento modules, the lack of a README mention leaves some uncertainty that this repository is the intended source.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, though organization backing and security scanning provide partial compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-sitemap Version >=100.3.0 | — | — |
smile/module-scoped-eav Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.