The package has a clear README, a declared GPL license, one runtime dependency, and no install-time scripts. Its single release and quiet repository leave limited evidence of sustained maintenance, while the workflow audit found high-confidence template-injection patterns. The repository also lacks a security policy and automated security scanning.
64%
Total Score
75
100
86
75
This is a young package, about 120 days old, with only one release and no established release cadence. That limits evidence of sustained maintenance but does not indicate abandonment by itself.
The repository recorded no commits and no active maintainers in the last three months. Because the project is young and was pushed on the release date, this is a maintenance concern rather than severe abandonment evidence.
The repository uses Composer, but no security-scanning tool was detected. This weakens supply-chain transparency somewhat, while the presence of a defined build tool provides limited compensation.
No repository security policy was found. For a small plugin this is not evidence of unsafe code, but it reduces transparency about vulnerability reporting and maintenance expectations.
Both workflows were analyzed successfully and all three action references are pinned, with no untrusted checkouts or script-injection findings. However, the release workflow has six high-confidence template-injection findings, which is a meaningful workflow-hygiene concern even without a dangerous trigger or sink corroborating it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.