The release has no declared or detected license, and the repository has had no commits in the last three months. It is backed by an organization, has a matching repository, clear installation documentation, and release notes for this version.
65%
Total Score
75
100
81
75
No license declaration or license file was found in the package or repository, leaving the legal terms for using this dependency unclear.
Five releases over about three years, including one in the last 12 months, show intermittent maintenance rather than abandonment, but the cadence is modest.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release provides some compensating evidence, but current maintenance activity is still limited.
Composer is used for the build, which fits the package ecosystem, but no security scanning tooling was detected, leaving a modest transparency gap.
The repository has no security policy. For a small checkout extension this is not severe on its own, but it reduces clarity about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
hyva-themes/magento2-default-theme Version >=1.3.12 | — | — |
hyva-themes/magento2-hyva-checkout Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.