The linked source has 70 commits in three months from three active contributors, with tests, a changelog, and an MIT license. GitHub Actions are fully audited but all 10 action references are unpinned, and no security policy is published.
22%
Total Score
100
64
50
Packagist marks the entire package as abandoned and names jalendport/craft-preparse as its replacement, making this release unsuitable for a new dependency despite the active source repository.
The package has 29 releases since June 2020 but no registry release in the last 12 months, which weakens confidence in this specific published package; recent repository commits partly compensate for that gap.
The repository name does not match the registry package name and its README does not mention the package, so the registry-to-source relationship is less transparent than expected.
The repository has no published security policy, leaving reporting and response expectations unclear; this is a genuine transparency gap but not evidence of abandonment by itself.
Version 3.0.0-alpha.2 is explicitly a prerelease, so its API and behavior may still change and it is a poor default for production dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
nystudio107/craft-code-editor Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.