This release appears generally suitable to depend on: it is actively released, with 32 releases over 828 days and 13 releases in the last 12 months, is stable and not deprecated, has an identified organization-owned repository, tests, a license file, and recent activity from two maintainers. The main concerns are transparency and repository linkage: the linked repository neither matches the package name nor mentions it in its README, and the repository lacks a security policy, security-scanning tooling, and explicit top-level workflow permissions. These issues warrant review of provenance and CI configuration, but they do not outweigh the strong release and maintenance evidence.
78%
Total Score
100
100
83
75
The repository name does not match tagginggroup/gtm and its README does not mention the package, creating a provenance and package-to-repository linkage concern despite the ordinary possibility of a related Magento repository.
The repository has zero stars and two forks, providing little external adoption evidence; popularity is supporting evidence only, so this is a modest concern rather than a health verdict.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-hygiene gap in the repository.
No repository security policy was found, which reduces transparency for vulnerability reporting and response.
The sole workflow lacks top-level GitHub Actions permissions, so its effective permissions are not explicitly constrained in the repository metadata.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
magento/framework Version ^102.0 || ^103.0 | — | — |
magento/module-eav Version ^100.0 || ^101.0 || ^102.0 | — | — |
magento/module-quote Version ^101.0 | — | — |
magento/module-sales Version ^100.0 || ^101.0 || ^102.0 || ^103.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.