It includes a README, repository license, tests, and no install-time scripts. Its focused Magento dependencies and published security policy add useful transparency.
78%
Total Score
67
100
89
100
The repository owner is an individual rather than an organization, so the concentrated contributor activity is not supported by visible organizational handoff capacity.
All two recent commits came from one contributor, so maintenance depends heavily on a single person. The active recent commits partly offset, but do not remove, that concentration risk.
The repository has nine stars and three forks, indicating a small user and contributor footprint. Popularity is supporting evidence, so this modest reach lowers confidence more than it lowers the health assessment.
Composer is used for builds, but no security-scanning tools were detected. That is a transparency and hygiene gap, not evidence of a specific security failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ~102.0||~103.0 | — | — |
magento/module-tax Version ~100.3||~100.4 | — | — |
magento/module-quote Version ~101.1||~101.2 | — | — |
magento/module-store Version ~101.0||~101.1 | — | — |
magento/module-catalog Version ~103.0||~104.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.