The repository is clearly tied to the package, has tests and a changelog, and shows two active contributors. Its single-release history and lack of a security policy leave little evidence of long-term maintenance.
72%
Total Score
88
100
88
83
Only one account can publish releases, which limits registry publishing redundancy, although repository activity shows another active contributor.
This is the first release, published less than a day ago, so there is no track record for judging sustained maintenance or release stability.
Composer is used as a build tool, but no security scanning tool was detected, leaving automated security coverage limited.
The repository has no security policy, so users lack documented guidance for reporting vulnerabilities or receiving security fixes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.