The project has recent releases, clear documentation, and an MIT license. Use the replacement package arnoson/kirby-form-builder instead of adding this abandoned package.
22%
Total Score
50
80
50
Packagist marks the entire package abandoned and explicitly identifies arnoson/kirby-form-builder as its replacement. That makes this release unsuitable for a new dependency despite the source project remaining active.
There were no commits and no active maintainers in the repository during the last 3 months. The recent release limits the concern, but the lack of current commit activity weakens maintenance confidence.
The linked repository has no security policy. This is a transparency gap for a form-handling package, though it is secondary to the package being abandoned and does not itself establish unsafe code.
Both workflows were analyzed successfully, with no untrusted checkouts or script injection. However, all 4 action references are unpinned and the audit found a high-severity but low-confidence cache-poisoning pattern plus a high-confidence adhoc package install, so workflow hygiene is below ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mzur/kirby-uniform Version ^5.3 | — | — |
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.