The package is small, clearly licensed, and backed by a matching organization-owned repository with a stable release. Its registry has seen no release in over five years, and the repository has had no commits in over two years. There is also no security policy or automated security scanning.
58%
Total Score
75
100
78
75
The package has had no release in over five years, despite 13 releases overall; its earlier release cadence shows it was once maintained but is now stale.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project whose latest push was over two years ago.
The repository has zero stars, three forks, and one watcher, providing little evidence of a broad user or reviewer community; this is supporting evidence rather than a verdict.
Composer is used as the build tool, but no security scanning tools are configured; the latter is reflected separately in the security-policy concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.4.0-RC1 | — | — |
campaignmonitor/createsend-php Version ^6.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.