The README and release notes make setup and this version’s changes clear. Install-time setup hooks, a broad dependency set, and no security policy add maintenance overhead for adopters.
66%
Total Score
50
50
94
50
The boilerplate declares 12 runtime dependencies, including Craft CMS and multiple plugins. This is plausible for its stated purpose but creates a wider upgrade and compatibility surface.
The package runs post-install commands that perform setup, database import, npm installation, and script removal. That behavior fits a project boilerplate but adds install-time side effects and operational risk.
The registry namespace is an organization name, but the linked repository is owned by an individual account. The ownership context does not show clear organization backing, limiting confidence in maintainer capacity.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful sign of slowed maintenance despite the package’s recent release history.
Composer is used as the build tool, providing expected project tooling. No security scanning tools are configured, leaving automated vulnerability coverage weaker.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ether/seo Version 5.0.0 | — | — |
wrav/oembed Version 3.1.6 | — | — |
craftcms/cms Version 5.8.21 | — | — |
craftcms/aws-s3 Version 2.2.3 | — | — |
verbb/navigation Version 3.0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.