The package has a clear README, license, changelog, stable versioning, and a recent release. Maintenance capacity is currently uncertain, while the release workflow has broad write access, an unpinned action, and a high-confidence template-injection warning.
62%
Total Score
50
100
94
50
There were no commits and no active maintainers in the last 3 months. Although the recent release history is reassuring, the current lack of source activity raises maintenance risk.
The repository has 12 open issues but no issues or pull requests were opened, closed, or merged in the last month, suggesting limited visible project interaction.
Composer is used for builds, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. That weakens the documented process for reporting and handling vulnerabilities, though it does not by itself show an active defect.
The sole workflow grants top-level write permissions, uses its only action unpinned, and has a high-confidence template-injection finding. No untrusted checkout or script-injection trigger was detected, so these are workflow hygiene concerns rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
softcommerce/module-core Version * | — | — |
magento/module-url-rewrite Version ^101|^102 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.