The package has tests, a changelog, a clear license, and 71 recent commits from two active contributors. Its repository is small and lacks a security policy, while workflow actions are not pinned, so maintenance and build-integrity safeguards remain limited.
73%
Total Score
100
100
81
50
Only two releases exist, both published on the same day, so there is very little release history from which to judge long-term stability. Recent repository activity partly compensates for the package's limited age.
Composer is used for builds, but no security-scanning tooling is reported. This is a modest transparency and maintenance gap, not evidence of an unsafe release by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a hygiene gap for a Moodle activity handling user submissions.
Version v0.1.2 is pre-1.0, which signals an immature compatibility contract, although it is not marked as a prerelease and the recent development activity is substantial.
Both workflows were analyzed successfully and no high-confidence audit findings or untrusted checkouts were reported. However, all five action references are unpinned and one workflow grants top-level write access, weakening build reproducibility and least-privilege hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version ^5.2 | — | — |
moodle/composer-installer Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.