The repository includes tests, a changelog, a clear README, and no install-time scripts. Its very recent history, single active contributor, missing security policy, and loosely pinned workflow actions leave meaningful maintenance and build-integrity concerns.
68%
Total Score
50
80
67
The package is less than a day old and has only two releases, so there is not enough history to demonstrate sustained maintenance or release reliability.
All three recent commits came from one contributor, leaving no demonstrated handoff capacity for maintenance if that contributor becomes unavailable.
Only three commits were recorded in the last three months; because the project is newly published, this is limited evidence rather than proof of abandonment.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities in a security-sensitive Moodle plugin.
Version v0.1.2 is not a stable major release, which indicates an early-stage API and compatibility profile despite not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version ^5.2 | — | — |
moodle/composer-installer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.