The license files disagree about whether this is LGPL or GPL, and the project has no published security policy. A README, changelog, organization-backed repository, and frequent recent releases provide useful transparency and support.
62%
Total Score
75
79
50
The manifest declares LGPL-3.0-or-later, while the artifact license file is detected as GPL-3.0. Both provide licensing evidence, but the mismatch creates uncertainty about the terms consumers should follow.
The package runs post-install and post-update Composer scripts. These increase installation-time behavior and maintenance surface, though the signal does not show that the scripts are unsafe.
The repository recorded zero commits and zero active maintainers in the last three months. Recent releases provide some compensating evidence, but the lack of current source activity still raises maintenance concern.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a hygiene limitation rather than evidence that the package is unsafe.
The repository has no SECURITY policy. This weakens disclosure transparency and gives maintainers and users no documented process for handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ~100.0||~101.0||~102.0||~103.0 | — | — |
magento/module-store Version ~100.0||~101.0||~102.0||~103.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.