The beta status and small community leave less evidence of long-term stability. No security policy or automated security scanning is documented, although the project remains owned by an organization and includes a README and changelog.
62%
Total Score
75
100
71
75
The package has existed since September 2019 with 17 releases, but only one release in the last 12 months, indicating a slow current cadence rather than abandonment on its own.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, even though the latest release was published recently.
The repository has 4 stars, 1 fork, and 6 watchers, indicating a small user and contributor community. Low popularity is supporting evidence only and does not by itself make the package unsafe to adopt.
Composer is used as a build tool, but no security-scanning tools are configured. The missing scanning is a hygiene concern rather than evidence of abandonment or malicious behavior.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it is not by itself a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.