Its stable version, small runtime dependency set, and organization-backed repository make the package straightforward to evaluate. Low adoption, no recent commits, and the repository’s weak package linkage increase maintenance and ownership uncertainty.
54%
Total Score
75
100
78
50
The package has had 5 releases, but none in the last 12 months; its latest release was 17 months ago. This indicates materially slowing maintenance, with no newer release evidence to offset it.
There were no commits and no active maintainers in the last 3 months, which is direct evidence of currently inactive development. The non-archived, organization-owned repository provides only partial compensation.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly demonstrated. This creates ownership and provenance uncertainty.
The repository has 1 star, 1 fork, and 4 watchers, providing little evidence of broad community support. Popularity is supporting evidence, so this is a modest concern rather than a decisive risk.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap that modestly reduces transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version ^100.1|^101.0|^102.0|^103.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.