The package is licensed and has repository tests, a changelog, and release notes. Its low popularity is not a concern given four active contributors and organization backing.
82%
Total Score
100
86
50
The package is only 28 days old, with 12 releases and a median interval of about 3 hours. This shows active delivery but leaves limited evidence of long-term stability.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The workflow audit completed cleanly with no untrusted checkouts or script-injection findings, but all 12 action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
craftcms/commerce Version ^5.0.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.