Its MIT license, matching repository, and clean package structure improve transparency. Security tooling is absent, and the small project has limited evidence of long-term maintenance.
72%
Total Score
100
100
83
83
The package is young at 154 days and has four releases, including four in the last 12 months; this shows active initial publishing but limited long-term history.
The repository has one star and no forks or watchers, providing little independent evidence of adoption. This is only a supporting concern for a specialized module, not a severe risk by itself.
Composer is used for builds, but no security-scanning tools are present, leaving a meaningful repository hygiene gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities.
No GitHub Actions workflows were present to audit, so there are no detected workflow risks; this also provides no evidence of automated checks or secured release automation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
smile/elasticsuite Version * | — | — |
hyva-themes/magento2-smile-elasticsuite Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.