Its focused README and minimal runtime dependency make the package straightforward to integrate. The release workflow is fully audited, but one action is unpinned and no security policy is published.
68%
Total Score
83
100
93
75
No declared license, license file, or repository license file was detected. That leaves the legal terms for using this dependency unclear.
All six recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
The repository has no published security policy. This is a transparency and reporting gap, though it is not evidence that the package is unsafe.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Its one action is unpinned, which is a modest reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0|^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.