The source includes tests, a changelog, a clear README, and a security policy. Its narrow contributor base and unpinned workflow images add operational risk for a dependency with an old published release.
64%
Total Score
83
100
79
100
Only two releases exist, with the latest published on July 29, 2020 and none in the last 12 months. This is a meaningful concern for registry consumers, although recent repository commits provide some compensating maintenance evidence.
All five recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization backing partly offsets this concentration but does not remove it.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap rather than evidence of abandonment.
Version 0.0.2 is not a stable major release, so the public API may still change more readily than in a mature 1.x package.
All five workflows were analyzed and no untrusted checkouts or script injection were found, but all six action references are unpinned and four high-confidence unpinned-image findings affect CI reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102.0|^103.0 | — | — |
magento/module-catalog Version ^102.0|^103.0|^104.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.