The MIT declaration and small, focused artifact reduce licensing and complexity concerns. Missing consumer documentation, security tooling, and a security policy weaken transparency, while the project shows no demonstrated maintenance capacity beyond its initial release.
45%
Total Score
50
72
83
This package has only one release, published about 4 years and 5 months ago, with no releases in the last 12 months. That is strong evidence of limited ongoing maintenance for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of releases since April 2022. The lack of recent work materially increases abandonment risk.
The artifact has no README, tests, or changelog; missing tests and changelog are normal for published artifacts, but the missing README reduces consumer transparency for a Magento module. The repository does use GitHub Releases, providing only limited documentation compensation.
The repository has 0 stars and 0 forks, with 1 watcher. Popularity is only supporting evidence, but these very limited adoption signals provide no meaningful external indication of active project backing.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tools were detected. This is a modest repository hygiene and transparency gap rather than a severe risk by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.