The module has a long release history, a current stable version, tests, a changelog, and a security policy. Organizational ownership provides some continuity; pin version 3.10.7 and monitor future maintenance.
72%
Total Score
67
94
100
One contributor made all 6 commits in the last 3 months, giving the project a concentrated short-term bus factor. Organizational ownership provides some handoff capacity, but no second recent contributor is shown.
The repository received 6 commits in the last 3 months, showing recent maintenance, but all activity came from one active maintainer. The activity is positive while still indicating limited ongoing capacity.
Composer is used as a build tool, but no security scanning tool was detected. The missing scanner is a modest transparency and maintenance concern, not evidence of abandonment.
All 5 workflows were analyzed successfully and have no untrusted checkout or script-injection findings, but all 6 action references are unpinned and two workflows use floating or unpinned container images. These high-confidence hygiene issues weaken build reproducibility and supply-chain controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1 || ^2 || ^3 | — | — |
magento/framework Version ^102.0 || ^103.0 | — | — |
magento/module-eav Version ^100.0 || ^101.0 || ^102.0 | — | — |
magento/module-tax Version ^100.0 | — | — |
magento/module-quote Version ^101.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.