The library has no README or documented release notes for consumers, and its repository has no security policy or scanning tools. Its stable version and small dependency footprint do not offset the long maintenance gap.
42%
Total Score
30
50
The latest release was in July 2017, with no releases in the last 12 months and only three releases overall. This is strong evidence of abandonment risk for a dependency.
The repository is not formally archived, but it was last pushed in July 2017, providing no sign of source maintenance since then. The active archive status only partly offsets the age of the project.
The package has no README, tests, or changelog. Missing tests and changelog are normal in published artifacts, but a library without consumer documentation is a genuine transparency and integration gap.
The repository has zero stars, forks, and watchers, so there is no visible community support to compensate for the long period without releases or repository updates. Popularity is only supporting evidence.
Composer is used for builds, which is appropriate, but the repository reports no security-scanning tools. This is a supporting hygiene weakness rather than evidence of an unsafe release by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version 100.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.