Usable with caveats: it has frequent stable releases and an active, non-archived repository, but all recent commits come from one contributor. The repository also does not clearly identify this package and lacks security-policy coverage.
68%
Total Score
50
100
78
75
The artifact has a README and changelog, and the repository uses GitHub Releases, but neither the package nor repository contains tests. For a 205-file Magento module, that is a meaningful maintenance and regression-testing gap.
The registry namespace is softcommerce, while the repository owner is the user account softcommerceltd rather than an organization. This provides some ownership linkage but limited evidence of institutional maintenance depth.
One contributor made 100% of the 8 commits in the last 3 months. Because project backing identifies a user-owned repository rather than an organization-owned one, there is no provided organizational compensation for this concentration.
There were 8 commits in the last 3 months, showing recent work, but only one active maintainer made them all. Activity exists, yet maintenance capacity is narrow.
The repository has 14 open issues but no new or closed issues and no pull-request activity in the last month. This is a modest concern about issue follow-through, though release activity compensates for some of it.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102||^103 | — | — |
magento/module-ui Version ^101 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.