The project has a small maintenance footprint and limited security hygiene. Its proprietary license may not fit an open-source dependency policy, despite a recent release and documented release notes.
58%
Total Score
50
70
50
The package declares a proprietary license and includes LICENSE.md files in both the artifact and repository, so licensing is explicit but may restrict adoption as an open-source dependency.
The package has four releases over about 2 years and 4 months, with two releases in the last 12 months. This shows ongoing delivery, but the cadence is modest for a dependency.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although a release was published recently, the current absence of development activity raises maintenance risk.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap for a package with release automation.
The repository has no security policy. For a small plugin this is a hygiene gap, though it does not by itself show abandonment or unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0|^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.