The source includes tests, a changelog, clear usage documentation, a matching license, and a security policy. Recent commits show activity, although one contributor handles them; organization backing reduces that concern.
68%
Total Score
88
100
83
100
The package has five releases over about five and a half years, with a median interval of about 14 months and no releases in the last 12 months. This indicates slow maintenance, though the repository was recently pushed.
All five commits in the last three months came from one contributor. The organization-owned repository provides some capacity for handoff, but observed contribution remains concentrated.
Composer build tooling is present, but no security scanning tools were detected. The existing workflow audit and repository security policy provide partial compensating transparency.
Version 0.0.6 is not a prerelease, but the package remains below a stable 1.0 major version, which modestly reduces maturity confidence.
All five workflows were analyzed, with no untrusted checkouts or script injection, but four high-confidence findings show container images using floating or unpinned tags. This weakens build reproducibility and CI supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^100.1|^101.0|^102.0|^103.0 | — | — |
magento/module-quote Version ^100.1|^101.0 | — | — |
magento/module-checkout Version ^100.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.