The project has thorough documentation and tests, with two contributors making 57 commits in three months. Its very recent release history and unpinned workflow actions leave maturity and build reproducibility concerns.
68%
Total Score
100
100
75
75
The package is brand new, with only two releases and both published within the first day of collection. That leaves too little history to establish long-term maintenance or release reliability.
The repository has no stars, forks, or watchers. For a package released only hours ago, this is weak supporting evidence but not a maintenance verdict on its own.
Composer is used for builds, but no security scanning tools are configured. The missing scanning reduces supply-chain assurance, although it does not by itself indicate unsafe code.
The repository has no security policy. For a plugin that handles conference tickets, attendance, and user data, the absence reduces transparency about vulnerability reporting and response.
Version v0.1.2 is not marked as a prerelease, but the 0.x major version signals an early-stage API and limited maturity. This is a moderate adoption concern rather than evidence of abandonment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version ^5.2 | — | — |
moodle/composer-installer Version ^1.0 | — | — |
adamjenkins/moodle-mod_confprogram Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.