The package includes tests, a changelog, a README, and a long release history. Its single-maintainer structure and limited repository security hygiene leave more ownership and maintenance risk than the release cadence suggests.
67%
Total Score
50
100
88
50
Only one registry account has publish access. The package has a long release history, but a single publisher leaves limited visible redundancy if that maintainer becomes unavailable.
The repository recorded zero commits and zero active maintainers in the last 3 months, which indicates a recent pause in source activity. The recent registry releases and July push partly offset this, but not completely.
The repository name does not match the package name and its README does not mention the package. Although the owner and package namespace align, the missing direct reference creates uncertainty about repository ownership.
The repository uses Composer, but no security-scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
No repository security policy was found. For a small plugin this is a limited documentation gap, but it leaves vulnerability-reporting expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
composer/installers Version ^2.0 | — | — |
hypejunction/forms_api Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.