The package has a clear README, a stable version, and a small runtime dependency set. Maintenance evidence is thin, with no commits in the last three months, no security policy, and licensing not substantiated by a file. The linked repository also does not name or mention this package.
58%
Total Score
50
100
71
50
The manifest points to LICENSE.md, but no license file was found in either the package or repository and no detected license is available. The release therefore has no substantiated license evidence.
The package has 15 releases since February 2024, but only 1 release in the last 12 months, indicating a slow recent cadence despite the latest release being recent enough to show the project is not entirely abandoned.
The repository recorded zero commits and zero active maintainers in the last three months. That is meaningful evidence of limited current maintenance capacity, even though a release was published during the broader period.
The repository name does not match the package name and its README does not mention the package. This raises caution that the repository relationship is not clearly documented, although the matching theme-oriented file tree provides some context.
Composer build tooling is present, but no security scanning tooling was detected. This is a modest transparency and maintenance gap rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=102.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.