Two contributors split 14 recent commits, and the package includes tests with a clear MIT declaration. No security policy or automated security scanning is visible, and the published package has no README for consumers.
67%
Total Score
83
100
75
83
Tests are present in both the package and repository, which supports basic project maturity; the missing README is a minor consumer-facing gap for a Craft CMS integration package.
The repository is owned by an individual user rather than an organization, so the small two-person contributor base offers limited demonstrated handoff capacity.
The package is only 66 days old and has two releases, with both released within about 1 day; this shows initial activity but provides little evidence of long-term maintenance.
Composer build tooling is present, but no security scanning tool was detected; that is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.