There is no security policy and the repository has little adoption evidence. Clear licensing, tests, and an organization-owned source repository provide useful support.
67%
Total Score
83
100
86
75
This is a young package, 52 days old, with only one release and no established release interval. That limits evidence of long-term maintenance and stability.
All 27 recent commits came from one contributor, so maintenance continuity depends heavily on one person. Organization backing helps provide a handoff path but does not remove the current concentration.
The repository has one star, no forks, and no watchers, offering little independent adoption evidence. Popularity is supporting evidence only, so this is a modest concern rather than a decisive risk.
The repository has no security policy or documented security-reporting process, leaving an important transparency and incident-response gap for a CMS plugin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.4 | — | — |
magna-cms/plugin-sdk Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.