A clear license, README, and release notes make the package easier to evaluate. There is no security policy, while the repository has only 2 stars and no recorded issue activity; those are weak evidence at this age.
70%
Total Score
100
92
67
The package is 0 days old with only 3 releases, so there is not enough history to demonstrate sustained maintenance or reliable release practice.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented for a package that operates inside a CMS project.
The sole workflow grants top-level write permissions and both of its action references are unpinned. No untrusted checkout or script-injection path was found, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/cms Version >=5.1 | — | — |
getkirby/composer-installer Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.