The package includes a README, changelog, and a small runtime dependency footprint. Its single-person backing, no recent commits, and lack of security tooling leave limited evidence of ongoing support.
58%
Total Score
50
100
83
83
Only one registry account has publish access. The repository owner is an individual rather than an organization, so there is limited visible maintainer redundancy.
Only two releases were published, both within about nine hours, followed by roughly one year without another release. This suggests a small or possibly inactive project, though the release history is still short rather than explicitly abandoned.
The repository had zero commits and zero active maintainers in the last three months, and its last push was about one year ago. That is meaningful evidence of limited ongoing maintenance.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community use or review. Popularity is only supporting evidence, so this modestly lowers confidence rather than determining the verdict.
Composer build tooling is present, but no security scanning tools are configured. For a module handling webhook credentials and order data, this weakens maintenance and review evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 103.*|104.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.