Organization ownership, a clear README, and only one runtime dependency support adoption. Limited security tooling and a very small user base warrant pinning 1.0.1 for this Magento integration.
54%
Total Score
75
100
81
50
The package has only two releases and none in the last 12 months; its latest release was in July 2022, indicating prolonged inactivity for a dependency.
There were zero commits and zero active maintainers during the last three months, consistent with the repository's last push in July 2022 and raising abandonment risk.
The repository has one star, no forks, and four watchers, showing very limited visible adoption; organization backing partly compensates, but this remains weak supporting evidence.
Composer is used as the build tool, but no security scanning tools are configured, leaving a modest transparency and maintenance-hygiene gap.
The linked repository has no security policy, which makes vulnerability reporting less transparent; this is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swissup/module-core Version ^1.12.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.