The repository is small and clearly tied to the package, with a matching README, license, and release notes. It is brand new, has no recorded recent commits, and lacks security scanning, so maintenance maturity is not yet demonstrated.
64%
Total Score
67
100
88
75
Only one registry maintainer is listed, which leaves limited visible publishing redundancy for a user-owned project. The linked repository confirms the same owner, but does not provide evidence of a broader maintainer base.
The package is 0 days old, with all 4 releases published on the same day. That is too little history to establish a dependable maintenance pattern, although it may simply reflect a new project.
The repository shows 0 commits and 0 active maintainers in the last 3 months. Because the package is also 0 days old, this is partly explained by its launch date, but it still leaves maintenance capacity unproven.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are configured. The missing scanning is a modest transparency and maintenance-hygiene gap.
The repository has no security policy. For a small control-panel plugin this is not a severe risk, but it leaves vulnerability reporting and handling expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.