Comprehensive tests, clear licensing, and a security policy support dependable integration. Workflow actions are unpinned and the repository has no security scanning, so keep CI provenance under review.
78%
Total Score
75
93
75
All 17 commits in the last 3 months came from one contributor, creating concentration risk. Organization backing provides some handoff capacity, but does not remove the current single-contributor dependence.
Composer build tooling is present, but no security-scanning tools were detected. That leaves a meaningful supply-chain hygiene gap despite the otherwise active project.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both referenced actions are unpinned, weakening build reproducibility and CI supply-chain controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.12 | — | — |
mage-obsidian/module-modern-frontend Version ^2.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.