Release notes and a repository changelog improve transparency, while two recent contributors provide some maintenance capacity. The missing security policy and broad workflow permissions leave meaningful process gaps.
68%
Total Score
100
100
86
75
The package is 131 days old and has only one release, so its long-term maintenance record is not established. The repository has since received commits, which partly offsets the limited registry history.
The repository uses Just and Composer build tooling, but no security-scanning tool was detected. That is a modest process gap for a new package.
No repository security policy was found, leaving no documented route for reporting vulnerabilities or describing security handling.
Both workflows grant top-level write permissions, and the sole action reference is unpinned, creating workflow-hygiene concerns. The pull_request_target workflow has no untrusted checkout or script-injection sink, while the high-confidence bot-condition and template-injection findings remain issues to review rather than standalone proof of severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.