Documentation, tests, release notes, and a security policy make this straightforward to evaluate. Workflow container images are not pinned, so builds can change without a package release.
72%
Total Score
83
100
88
88
Only four releases have been published since July 2020, with no registry release in the last 12 months and the latest release in April 2024. Recent repository commits partly offset the quiet registry cadence, but release availability remains a maintenance concern.
All five recent commits came from one contributor, which concentrates practical maintenance capacity. Organization ownership provides some ability to hand off maintenance, so this is not a severe risk.
Composer build tooling is present, but no security-scanning tool was detected. The repository's security policy and tested CI provide some compensating transparency.
All five workflows were analyzed without untrusted checkouts or script injection, but all six action references are unpinned and high-confidence findings identify floating or unpinned container images in integration and Playwright workflows. These are meaningful reproducibility and build-integrity weaknesses, though no broad write permissions were found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/module-quote Version ^101.0 | — | — |
magento/module-customer Version ^101.0|^102.0|^103.0 | — | — |
yireo/magento2-salesblock2 Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.