The MIT license, matching source tree, repository changelog, and stable version make the package straightforward to inspect and integrate. Its single-maintainer profile and absent security policy leave limited support and governance evidence.
58%
Total Score
81
75
The package has only one release, published 925 days ago, with no releases in the last 12 months. That is meaningful evidence of limited ongoing maintenance, though it does not prove abandonment for a small stable plugin.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little external evidence of maturity.
Composer build tooling is present, but no security-scanning tool was detected. This is a governance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a small package this is a modest transparency and response-process gap, not a standalone adoption blocker.
The single workflow was fully analyzed with no audit findings, no untrusted checkout, and job-level permissions, which is positive. Its one action reference is unpinned, leaving a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version 5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.