The package is small and clearly identified, with a stable 1.0.1 release, a usable README, and an explicit MIT declaration. It has no security policy or security-scanning tooling, which limits transparency for a production dependency.
43%
Total Score
0
78
75
The package has only two releases, both in May 2021, and none in the last 12 months; the latest release is over five years old. This is strong evidence of abandonment risk for a Magento dependency.
The repository had zero commits and zero active maintainers in the last three months, consistent with the package's long release silence. No provided signal shows current maintenance capacity.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than decisive, but these figures provide little external evidence of active use or review.
Composer is used for the build, which is appropriate, but no security-scanning tools are reported. That leaves a transparency and review gap for a production package.
The linked repository has no security policy. This is a modest transparency weakness, though it is less significant than the lack of recent release and commit activity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.