The stable release line and matching repository include tests and a changelog, supporting dependable use. One maintainer, three months without commits, and unpinned workflow actions reduce oversight and maintenance confidence.
68%
Total Score
67
100
94
83
A single registry maintainer is consistent with an individually owned project, but it leaves limited publishing redundancy when combined with the recent lack of commit activity.
There were no commits and no active maintainers during the last three months, which is a meaningful recent maintenance gap despite the broader release history.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed and has no dangerous sinks or audit findings, but both action references are unpinned, weakening build reproducibility and action-integrity controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.2 | — | — |
tijsverkoyen/css-to-inline-styles Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.