The repository matches the package, includes a clear setup README, and has a stable 0BSD license. Its install-time script and lack of security tooling add modest caution.
65%
Total Score
50
75
50
The package runs a post-root-package-install script during installation. This adds some supply-chain and reproducibility caution, though the signal does not show that the script is harmful.
The package has had no releases in roughly four years, with all three releases clustered on one day in September 2022. This strongly limits evidence of ongoing maintenance, although the package is explicitly a conference demo.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive since its 2022 release. Its demo-oriented purpose partly explains the inactivity but does not remove the abandonment risk.
The project uses Make and Composer for builds, which supports repeatable setup, but it reports no security scanning tools. That is a modest transparency and maintenance gap for a package with an install workflow.
The repository has no security policy. For a small conference demonstration this is a limited concern, but it leaves no documented channel or process for reporting security issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.2 | — | — |
vlucas/phpdotenv Version ^5.4 | — | — |
putyourlightson/craft-sprig Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.