A minimal portfolio and blog theme for Kirby CMS
76%
Total Score
healthy
Regular releases and recent commits support the package, while permissive, unpinned CI workflows hold it below the top tier.
Two contributors are active, although the leading contributor made 17 of 22 recent commits, or about 77%. The second contributor's five commits partly reduce the concentration concern.
Composer is used as a build tool, but no security scanning tool was detected. For this small theme, the missing scanner is a modest transparency gap rather than evidence of abandonment.
The repository has no SECURITY.md or other detected security policy. This weakens reporting transparency, though it is not by itself evidence that the package is unsafe.
The single workflow was fully audited with no untrusted checkout or script-injection trigger, but it grants top-level write permissions, leaves both action references unpinned, and has a high-confidence template-injection finding. These are avoidable CI hygiene and supply-chain weaknesses, although no dangerous trigger-and-sink combination was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.