The source includes tests, a README, and a clear license. CI leaves all six actions unpinned and offers no security policy, so pinning and ownership review are sensible.
68%
Total Score
50
67
50
This package is only hours old, with two releases and a median interval of about 7 hours. That shows active initial work but provides almost no evidence of sustained maintenance.
All 16 commits in the last 3 months came from one contributor, leaving no demonstrated handoff capacity for this user-owned project.
The repository name matches the package, which supports the linkage, but its README does not mention the package name. That leaves a small transparency concern about the repository-to-package relationship.
Composer build tooling is present, but no security-scanning tools were detected. For a small new plugin this is a hygiene gap rather than a severe adoption risk.
The repository has no security policy. This is a transparency and maintenance gap for a Moodle plugin, although it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version ^4.5 || ^5.0 | — | — |
moodle/composer-installer Version ^1.0 | — | — |
adamjenkins/moodle-local_sheetmusic Version >=0.2 <1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.