The package is small and clearly structured, with a README, matching source repository, and no install-time scripts. Its proprietary license may restrict adoption, while the project has had no release or commit activity for over two years.
58%
Total Score
75
71
75
The manifest declares a proprietary license, so the release is licensed rather than lacking licensing information. However, proprietary terms can limit use and redistribution in a dependency.
The package has had no releases in the last 12 months, and its latest release was over two years ago. Its five releases across roughly six years show a slow cadence rather than complete instability, but maintenance appears dormant.
The repository had no commits and no active maintainers in the last three months, consistent with the release history showing no releases for over two years. This materially raises abandonment risk.
The repository uses Composer for builds, which fits the package ecosystem, but it has no security scanning tools. The missing scanning is a hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency weakness, though the small package scope limits its weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
magento/module-store Version * | — | — |
magento/module-backend Version * | — | — |
magento/module-media-storage Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.