The package includes tests, a changelog, a matching repository, and recent commits from two contributors. Its automated workflows need tightening, especially the high-confidence bot check and two unpinned action references, while the missing security policy adds a smaller gap.
72%
Total Score
67
100
100
75
The registry and repository are owned by the same individual account, so ownership is clear, but there is no organization backing to offset the small maintainer base.
The lead contributor made 10 of 11 recent commits, leaving maintenance concentrated despite a second contributor being active.
The repository has no security policy, leaving disclosure and response expectations undocumented for consumers of a web-facing module.
Both workflows were analyzed, but all two action references are unpinned. A high-confidence bot-condition finding appears in a pull_request_target workflow with top-level write permissions; no untrusted checkout or script injection was found, limiting this to a meaningful hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.