The repository is intact and clearly matches the package, with a usable README and MIT license. Long-term release inactivity, no recent commits, and no security policy make this a risky dependency for new projects.
48%
Total Score
50
100
72
75
The last release was in October 2017, with no releases in the past 12 months. This long gap is strong evidence of low release maintenance, although the package may target an older Magento compatibility need.
The package and repository are backed by the same individual-owned namespace. This is coherent ownership, but it does not provide the capacity or redundancy of organizational backing.
There were no commits or active maintainers in the past three months. This weakens the recent-maintenance picture and only partly offsets the repository's recent push timestamp.
The repository has zero stars and one fork, so there is little community evidence to support ongoing adoption. Popularity is only supporting evidence, so this reinforces rather than determines the maintenance concern.
Composer is used as a build tool, but no security-scanning tooling was detected. That is a maintenance and transparency gap for a dependency intended for application integration.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.