The package has a clear MIT license and a small, focused artifact. Its maintenance signals indicate abandonment, so pinning it creates substantial long-term compatibility risk.
12%
Total Score
50
50
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on it.
The package has only one release, 1.0.0, and no releases in over five years. That leaves compatibility with current Magento and PHP versions unverified.
The source repository is archived and was last pushed over five years ago, showing that active maintenance has ended.
The repository has zero stars and one fork, providing little evidence of community adoption. This reinforces the maintenance concern but is not decisive alone.
The repository has no security policy. This is a transparency gap, though the archived and abandoned state is the more significant concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ~102.0.0|~103.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.