The repository is not archived, matches the package, and includes release notes, a README, and a changelog. Its small dependency surface and organization backing reduce adoption risk.
58%
Total Score
67
100
88
75
The package has 21 releases since June 2021, but it has had no registry release in roughly three years, which is a meaningful maintenance concern.
There were zero commits and zero active maintainers in the last three months, consistent with a project whose maintenance has substantially slowed.
No issues or pull requests were opened or closed in the last month, leaving little evidence of active support alongside the inactive commit record.
The repository uses Composer for builds, but no security scanning tools are configured; this is a modest transparency and hygiene gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.