Clear documentation, tests, release notes, and an MIT license improve confidence. The repository is young and single-maintainer, while all four workflow actions are unpinned; adoption is reasonable with those maintenance and build-hygiene limits.
68%
Total Score
50
100
94
50
One contributor made all 8 commits in the last 3 months, giving the project a bus factor of one. The repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset that concentration.
The repository recorded 8 commits in the last 3 months, showing ongoing work. However, all activity is concentrated in one active maintainer, limiting resilience if that person stops maintaining it.
Composer is used for builds, but no security-scanning tool was detected. This is a modest transparency gap for a plugin handling consent and personal-data workflows, not evidence of unsafe code.
The repository has no security policy. For a GDPR-focused plugin that processes consent and data requests, the missing disclosure path modestly reduces maintenance and vulnerability-reporting transparency.
Both workflows were fully analyzed with no injection, untrusted-checkout, or audit findings, and they do not grant top-level write access. However, all 4 of 4 action references are unpinned, leaving build inputs less reproducible and increasing supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
happytodev/blogr Version * | — | — |
filament/filament Version ^5.0 | — | — |
laravel/framework Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.