The stable release and declared MIT license make the project straightforward to inspect and adopt. Its individual-owned repository and lack of a security policy leave limited visible support for a long-lived dependency.
45%
Total Score
50
75
67
The package has had no release in 2 years 10 months, with zero releases in the last 12 months. That long pause is strong evidence of abandonment risk, despite the package having three releases overall.
A post-root-package-install script runs during installation. This adds execution during setup and warrants review, but the signal alone is not evidence that the package is unsafe or unmaintained.
The repository is owned by an individual account rather than an organization. That is not inherently unhealthy, but it provides less visible institutional backing for a dependency already showing prolonged inactivity.
The repository has zero stars and forks and one watcher. Low visibility is supporting evidence of limited adoption, but it does not by itself establish that a small starter project is unhealthy.
Composer is used as a build tool, but no security-scanning tools are present. The missing scanning support weakens maintenance hygiene for a project with several runtime dependencies.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.4.0 | — | — |
vlucas/phpdotenv Version ^5.4.0 | — | — |
craftcms/ckeditor Version ^3.6 | — | — |
verbb/knock-knock Version ^2.0 | — | — |
vaersaagod/matrixmate Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.