The project has only one recent contributor and no security policy, while the package README offers almost no usage guidance. Releases are regular and the repository is active, but the pre-1.0 version signals limited maturity.
65%
Total Score
67
100
79
75
The artifact includes a changelog and README, and the repository also has a changelog. The README is only 12 characters long, however, so consumer guidance is minimal.
One contributor made 100% of the single commit in the last 3 months. Organization ownership provides some handoff capacity, but observed maintenance remains concentrated.
The repository had only 1 commit in the last 3 months. That shows recent activity but a very low maintenance cadence.
Composer is used for builds, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. For a package integrated into Craft CMS applications, this leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.4.8 || ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.