Clear licensing, a useful README, and release notes support adoption. The small project has no security policy or automated security scanning, so future maintenance and oversight remain limited.
61%
Total Score
50
100
83
50
The package has only two releases and none in the last 12 months; its latest release was about two years ago. This indicates limited ongoing maintenance, though the releases were spaced about 35 days apart initially.
There were no commits and no active maintainers in the last three months, consistent with the package's roughly two-year release gap. This is a meaningful maintenance and abandonment concern.
The repository has 4 stars and 1 fork, indicating a small user and contributor footprint. Low popularity is supporting evidence only, but it provides little resilience if the sole maintainer stops work.
Composer is used for the build, but no security-scanning tool is present. For a Magento extension this leaves a modest oversight gap, without proving the package is unsafe.
The repository has no security policy, so there is no documented route for reporting or coordinating vulnerability fixes. This is a transparency gap, partly offset by the available source and README.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/magento2-base Version ~2.4.0 | — | — |
magento/module-customer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.