Its eight-module composition is clearly documented, licensed, and free of install-time scripts. The package and repository have seen no release or commit activity since January 2023, so future compatibility and maintenance are uncertain.
58%
Total Score
50
100
88
88
There were zero commits and zero active maintainers in the last three months, consistent with the lack of releases since January 2023 and indicating a meaningful abandonment risk.
This package has only one release, on January 6, 2023, with no releases in the last 12 months. That limits evidence of ongoing maintenance and compatibility work.
Composer build tooling is present, but no security scanning tools are configured. For this small metapackage, that is a modest transparency gap rather than a severe risk.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, though the package itself contains only dependency metadata.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
storefront-x/magento-module-sfx-store-config Version ^1.0 | — | — |
storefront-x/magento-module-email-url-extended Version ^1.0 | — | — |
storefront-x/magento-module-storeconfig-graphql Version ^1.0 | — | — |
storefront-x/magento-module-product-alerts-graphql Version ^1.0 | — | — |
storefront-x/magento-module-catalog-graphql-extended Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.