Its single maintainer and lack of post-release commit history leave little evidence of sustained maintenance. The workflow uses read-only job permissions, but all three action references are unpinned.
75%
Total Score
50
100
79
67
One registry maintainer is publishing the package. That is a limited continuity base, though the linked project is owned by the same individual.
This is the package's first and only release, published today, so there is no release track record yet; its very recent publication partly explains the lack of history.
There were no commits or active maintainers in the measured three-month period. Because the repository was created today, this is mainly an unproven maintenance record rather than evidence of abandonment.
The repository name matches the package, supporting that it is the intended source; the README does not explicitly mention the package name, a minor traceability gap.
The repository has no security policy. This is a transparency gap, but it is not by itself a severe dependency risk for this small plugin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version >=5.2 | — | — |
moodle/composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.