Clear documentation, tests, release notes, and a security policy improve confidence. Maintenance is concentrated in one contributor, and workflow images are unpinned, so updates deserve extra scrutiny.
68%
Total Score
83
100
88
83
The package has six releases since June 2024 and one release in the last 12 months, with version 1.0.5 released in October 2025. This indicates ongoing but relatively infrequent release activity.
All five recent commits came from one contributor, concentrating maintenance responsibility and increasing continuity risk. Organization backing partly compensates because responsibility can be handed off.
Composer is used for builds, but no security scanning tool was detected. The missing scanning is a modest hygiene gap rather than evidence of abandonment.
All five workflows were analyzed, but all six action references are unpinned and four high-confidence findings identify unpinned or floating container images. No untrusted checkout, script injection, or broad top-level write permission was found, but the reproducibility and supply-chain hygiene gap is material.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^102.0|^103.0 | — | — |
yireo/magento2-webp2 Version ^0.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.