The repository includes tests, a changelog, and a security policy, while organization backing provides some continuity. Pin the workflow container images before relying on its CI outputs.
78%
Total Score
67
100
94
83
One contributor made 100% of the 63 recent commits. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.
The repository had 63 commits in the last 3 months, but all came from one active maintainer, leaving limited contributor redundancy.
The repository name does not match the package name and its README does not mention the package, so the package-to-repository relationship is less transparent than expected despite the repository's plausible Loki Components identity.
All five workflows were analyzed, but four high-confidence findings show unpinned container images, including floating latest tags. There are no untrusted checkouts or script-injection findings, so this is a CI reproducibility concern rather than a severe adoption blocker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | ^2.0 | ^3.0 | — | — |
magento/framework Version ^103.0 | — | — |
loki/magento2-base Version ^1.3 | — | — |
laminas/laminas-http Version ^2.16 | — | — |
magento/module-quote Version ^101.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.