The package includes clear usage documentation, a release note, and no install-time scripts. Its license metadata conflicts with the MIT license file, while security scanning is absent and the workflow uses an unpinned action.
58%
Total Score
50
81
100
The artifact includes an MIT license file, but the manifest declares the package as proprietary. That mismatch creates avoidable licensing uncertainty for adopters.
The package has had no releases in more than two years, despite ten releases overall; this is meaningful evidence of reduced maintenance for a Magento development tool.
There were no commits or active maintainers in the measured three-month window, reinforcing the concern that maintenance has slowed substantially.
Composer build tooling is present, but no security scanning tools are configured. This weakens repository transparency and automated assurance without proving the package is unsafe.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but its only action use is unpinned. The missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.