The package is small and focused, with a clear MIT license and release notes for this version. Maintenance has been quiet for over a year, and its workflow uses broad permissions and unpinned actions.
61%
Total Score
50
83
75
The registry namespace and repository are owned by the same individual account, so ownership is consistent, but there is no organizational backing shown to compensate for the thin maintainer base.
The package has five releases since May 2024, but none in the last 12 months; the latest release was over a year ago. This indicates a meaningful maintenance slowdown, though the release history is established rather than abandoned outright.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. This raises maintenance and abandonment risk for a dependency.
The project uses Composer, which matches its PHP package ecosystem. No security scanning tooling was detected, a modest transparency and maintenance gap, but not a severe risk on its own.
The single workflow was fully analyzed and has no detected untrusted checkout or script-injection paths, but it grants top-level write permissions and all five action references are unpinned. These are workflow hygiene and supply-chain weaknesses without a detected dangerous sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/cms Version ^4.0 || ^5.0 | — | — |
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.