Organization backing, release notes, and repository tooling provide useful maintenance and publishing context. All four workflow actions are unpinned, and the repository has no security policy or clear package-name mention, leaving avoidable transparency and supply-chain gaps.
67%
Total Score
83
100
88
75
The package has six releases over about 3 years and 7 months, but none in the last 12 months; the latest release was about 1 year and 2 months ago. This indicates slowing maintenance, though not abandonment by itself.
There were no commits and no active maintainers in the last 3 months. Combined with no registry releases in the last 12 months, this is evidence of currently quiet maintenance.
The repository name does not match the package name and its README does not mention the package. This may be normal for a Magento submodule, but the collected evidence does not clearly connect the registry package to the repository.
No security policy was found in the repository, reducing transparency for vulnerability reporting and response.
All 4 of 4 action references are unpinned, so workflow dependencies can change without a reviewed version update. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
smile/module-custom-entity Version >=1.3.12 | — | — |
akeneo/magento2-connector-enterprise Version ^103.2 || >=104 | — | — |
smile/module-custom-entity-product-link Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.