The module is small and focused, with a clear README and only one runtime dependency. It also lacks a security policy, while its organization-backed repository provides limited evidence of ongoing care.
43%
Total Score
100
100
67
83
This package has had only one release, published over eight years ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
Neither the package nor the linked repository provides a declared or detected license file. This creates a real adoption and redistribution concern.
The repository has no stars or forks and only 23 watchers. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of broad adoption.
The repository uses Composer, which fits the package ecosystem, but reports no security-scanning tools. The missing scanning is a minor hygiene gap rather than a standalone adoption blocker.
The repository is not archived, but its last push was over eight years ago, so the unarchived status does not compensate for the lack of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^101.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.