The source project is still maintained and has a security policy, but all recent commits come from one contributor and its workflows use unpinned images. The package-level abandonment mark outweighs those positives.
20%
Total Score
83
50
100
Packagist marks the entire package as abandoned, with no replacement named. This package-level status is a severe adoption concern even though the linked repository remains active.
The latest release was about 17 months ago, and there were no releases in the last 12 months. That indicates stale published maintenance despite newer repository activity.
All 7 recent commits came from one contributor, creating a concentrated maintenance risk. Organization ownership provides some handoff capacity, so this is not severe on its own.
All five workflows were analyzed, but four high-confidence findings identify unpinned container images, including floating latest tags. These are build-reproducibility hygiene risks, without evidence here of an untrusted workflow trigger or credential exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.