The repository has a changelog, README, and release workflow, with organization backing. Its small release history and no commits in the last three months reduce confidence in ongoing support; all three workflow actions are unpinned.
58%
Total Score
75
83
50
Only 3 releases have been published, all within about 11 days, and none appeared in the last 12 months; the package has had no release for roughly 14 months. This is meaningful evidence of stalled maintenance, though the project is still relatively young.
The repository recorded 0 commits and 0 active maintainers during the last 3 months, reinforcing the release-history concern and reducing confidence in ongoing fixes.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, but it is not evidence that the package is unsafe by itself.
All 3 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit found no untrusted checkouts, script injection, or elevated top-level write permissions, so this remains a caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.