This is a small but currently maintained Magento package with a stable 1.0.2 release, a non-archived repository updated alongside the latest release, two active contributors with balanced commit share, and three merged pull requests in the last month. Its license, compact dependency profile, and absence of install-time scripts are positive indicators. However, the package is only 215 days old with three releases, has no tests or changelog in either artifact or repository, lacks a security policy and security-scanning tooling, and the linked repository neither matches the package name nor mentions it in its README, which creates a meaningful transparency concern. It appears usable, but dependency adoption should include verification that the repository is the intended source and additional project-level testing.
78%
Total Score
100
100
78
90
The package has a README, but neither the artifact nor repository contains tests or a changelog. For a payment module, the absence of repository tests is a genuine maintenance and verification gap.
The package is relatively young at 215 days and has only three releases, with a median interval of about 108 days. This is limited maturity evidence rather than abandonment, because the latest release was published recently.
The repository name does not match the package name and its README does not mention the package. Although name differences can occur with subpackages, the combination creates a meaningful risk that the linked repository is not clearly the package's intended source.
Composer is used as a build tool, but no security-scanning tools are present. The missing scanning is a transparency and hygiene gap, though it is not by itself evidence of unsafe code.
No SECURITY.md or equivalent security policy was found, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^100.1|^101.0|^102.0|^103.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.