The release includes clear notes, a matching source repository, and a security policy. Its small public footprint and no recent commits make long-term maintenance less certain.
66%
Total Score
75
100
88
83
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, even though the release history shows the project was active earlier.
The repository has only 2 stars and 1 fork, providing little external evidence of broad adoption or community support; popularity is supporting evidence, so this is a modest concern rather than a verdict.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap, partly offset by the repository's security policy.
The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Its sole action reference is unpinned, which is a limited reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.1.7 | — | — |
barrelstrength/sprout Version ^5.0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.