Tests, documentation, and a clear license improve the package's readiness. Two active contributors and 107 commits in three months show real work, while the missing security policy leaves less guidance for adopters.
72%
Total Score
100
80
50
This is a very new package with only 2 releases on the same day, so its long-term maintenance record is not established. Recent repository activity partly offsets that uncertainty.
The repository has no security policy, leaving adopters without a documented process for reporting vulnerabilities or understanding security response expectations.
Version v0.1.2 is pre-1.0, which signals an API and behavior surface that may still change substantially despite the release not being marked as a prerelease.
The audit completed successfully and found no untrusted checkouts, script injection, or high-confidence findings, but all 5 action references are unpinned and one workflow grants top-level write access. These are workflow hygiene and supply-chain concerns, not severe risks on their own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version ^5.2 | — | — |
moodle/composer-installer Version ^1.0 | — | — |
adamjenkins/moodle-mod_confsubmissions Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.