Clear documentation, tests, and release notes improve adoption. The repository has no security policy or scanning, and its single maintainer leaves limited demonstrated support capacity.
68%
Total Score
50
100
88
83
Only one registry maintainer, Justin Holt, is listed. The linked repository is user-owned rather than organization-owned, so there is limited visible redundancy if that maintainer becomes unavailable.
This is the first release, published 0 days ago, so there is no track record of fixes or sustained maintenance yet; the repository was also just pushed.
There were 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this is mainly missing history rather than established abandonment, but support capacity is unproven.
Composer is used for builds, but no security-scanning tools are configured, leaving less automated oversight for dependency or code issues.
The repository has no security policy, so users have no documented reporting and response process for security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.3.0 | — | — |
justinholtweb/craft-carrier Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.