It has a mature release history, a recent release, tests, and a working source repository. Unpinned CI actions and unclear repository ownership add avoidable uncertainty.
22%
Total Score
50
79
50
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption risk despite recent publishing activity.
The repository recorded no commits and no active maintainers in the last 3 months. Although the latest push was recent, this indicates a current pause in development.
The repository name does not match the package name and its README does not mention the package. This makes the package-to-source relationship less transparent, even though subpackages can legitimately use different repository names.
The repository has no security policy. For a small plugin this is a modest transparency gap, but it gives users no documented path for reporting vulnerabilities.
Both workflows were analyzed successfully and have no detected dangerous sinks or high-severity findings, but all 11 action references are unpinned. That leaves CI exposed to changes in referenced action code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
composer/installers Version ^2.0 | — | — |
hypejunction/menus_dropdown Version ~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.