Documentation is unusually complete, with a README, changelog, release notes, tests in the repository, and a matching organization-owned source project. The package has no install-time scripts and is not deprecated, but its proprietary license should be checked against your distribution requirements.
67%
Total Score
75
86
67
The package is extremely new, with two releases in less than one day and no established release history. That limits evidence of long-term maintenance and compatibility.
The repository records zero commits and zero active maintainers over the past three months. Although the repository was pushed recently and shows 29 merged pull requests in the past month, the commit metric gives limited evidence of sustained maintenance.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest repository hygiene gap rather than evidence of abandonment.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a package that integrates with Craft CMS and external services.
The sole workflow uses read-only permissions and has no detected dangerous audit findings, but all three action references are unpinned, so their contents can change without a version pin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.8 | — | — |
symfony/yaml Version ^6.4|^7.0|^8.0 | — | — |
guzzlehttp/guzzle Version ^7.8|^8.0 | — | — |
league/commonmark Version ^2.4 | — | — |
1994/ghostwriter-core Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.