This is a mature, actively published Craft CMS plugin with 122 releases over roughly 7 years, 14 releases in the last 12 months, a stable non-prerelease version, an unarchived organization-owned repository, documented tests and changelog, and no install-time lifecycle scripts. The main concern is that the repository recorded no commits or active maintainers in the last 3 months, despite six merged pull requests in the last month, so maintenance activity is somewhat inconsistent. Missing security-policy coverage, limited repository popularity, and permissive or absent workflow token-hardening reduce transparency and operational confidence, but do not outweigh the strong release history and project backing.
78%
Total Score
88
100
94
80
There were zero commits and zero active maintainers in the last 3 months, which is a genuine maintenance concern; the six merged pull requests in the last month partly compensate but do not fully establish ongoing commit activity.
Composer build tooling is present, but no security-scanning tools were detected. The absence of scanning lowers security-process transparency, though it is not by itself evidence of unhealthy maintenance.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap for a production plugin.
One workflow lacks top-level permissions and another declares top-level write access, so workflow token scope is not consistently minimized. This is a repository-hygiene concern, although dangerous workflow patterns were not detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.9.22 | — | — |
composer/composer Version ^2.9.3 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
google/cloud-translate Version ^1.15 | — | — |
spatie/guzzle-rate-limiter-middleware Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.