Usable with caveats: it is a clearly packaged, licensed, non-deprecated release with repository tests and recent activity. However, it is only 31 days old, has one release, and all recent commits come from one contributor, so long-term maintenance is unproven.
68%
Total Score
70
100
83
90
Only one registry account has publishing access. That is consistent with a user-owned project, but it leaves little publishing redundancy.
The repository is owned by a user account rather than an organization, so the single-contributor and single-publisher concentration is not visibly backed by an organization.
The package is only 31 days old and has a single release, so there is little evidence yet of sustained maintenance or release discipline.
One contributor made all four commits in the last three months, creating a concentrated maintenance dependency with no demonstrated backup contributor.
The repository has one star and no forks, providing little external adoption evidence. Popularity is supporting evidence only, so this modestly limits confidence rather than making the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.