The README leaves usage instructions unfinished, and the repository has no security policy or security scanning. The MIT license, matching repository, and organization backing provide useful transparency, but they do not offset the lack of ongoing maintenance.
42%
Total Score
0
70
50
This package has had only one release, on October 16, 2018, with no releases in nearly eight years. That is strong evidence of abandonment for a Craft CMS integration.
The repository recorded no commits and no active maintainers in the last three months; its last push was in November 2019, nearly seven years ago. This leaves compatibility and defect-fixing capacity doubtful.
The package includes a README and release notes for this version, but the README labels the description as work in progress and leaves usage documentation as TODO. The absence of tests and a changelog is normal for a published artifact, not a concern here.
The repository has no security policy, leaving no documented path for reporting vulnerabilities. This is a transparency and maintenance gap, although it is less serious than the inactive release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.