Its Composer-only shape keeps integration simple, and the stable major version avoids prerelease churn. The organization-owned repository is intact, but the project offers no license or security policy.
42%
Total Score
50
100
75
83
The package has only two releases, with the latest published over five years ago and none in the last 12 months. That is a substantial maintenance and abandonment concern, despite the package not being registry-deprecated.
The repository had zero commits and zero active maintainers in the last three months. Combined with the old release history, this materially increases abandonment risk.
No declared license or license file was found for the release or repository. This creates a material legal and transparency concern for dependency adoption.
Composer is used as the build tool, which fits the package type, but no security scanning tooling was detected. The missing scanning is a moderate hygiene gap rather than proof of unsafe code.
The repository has no security policy. For a small meta-package this is a transparency gap, though it is less serious than the lack of licensing and recent maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/product-community-edition Version ^2.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.