Overall, this looks like an actively maintained Magento 2 module release: it has recent releases (latest on 2026-08-18), a non-deprecated registry status, a complete artifact with README/tests/CHANGELOG, and a living repository that is not archived. However, there are meaningful process/operational risks: repository maintenance is highly concentrated (top contributor holds ~98% of recent commits), there is no evidence of security scanning tooling, and the linked repository does not appear to reference the package name in its README (possible mismatch/monorepo ambiguity). These concerns keep it out of the “highly safe” band, but it remains usable with caution.
62%
Total Score
80
100
89
90
Only one registry maintainer is listed (Jisse Reitsma (Yireo)). While that can be normal for small extensions, it increases bus-factor sensitivity.
Commit responsibility is extremely concentrated: the top contributor accounts for ~97.8% of commits in the last 3 months, which increases the risk if that contributor becomes unavailable.
The linked repository does not match the package name and does not mention the package in its README (repo_name_matches_package=false, package_name_in_readme=false), which raises ambiguity about repository ownership or packaging scope.
The repository uses composer for builds but there is no security scanning tool evidence collected, leaving fewer automated defenses against vulnerabilities.
All analyzed workflows appear to lack top-level permissions configuration (5/5 without top-level permissions). This does not prove vulnerability, but it reduces assurance that least-privilege is enforced.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
symfony/mime Version ^6.0|^7.0 | — | — |
symfony/console Version ^5.0|^6.0|^7.0 | — | — |
magento/framework Version ^101.0.1|^101.1|^102.0|^103.0 | — | — |
magento/module-ui Version ^101.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.