The package includes a clear README, changelog, license file, and a small runtime dependency profile. Its repository remains unarchived and organization-backed, but the available maintenance evidence is too old for a dependable current dependency.
42%
Total Score
50
100
75
83
The latest release was in July 2021, with no releases in the last 12 months and only three releases overall. This indicates prolonged abandonment risk despite a prior release cadence of about 53 days.
The repository recorded zero commits and zero active maintainers over the last three months, consistent with the package's long release gap. This materially lowers confidence in ongoing maintenance.
Three issues remain open, with no issues or pull requests opened or closed in the last month. The lack of recent issue resolution adds to the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. For a package intended for application integration, this reduces transparency around vulnerability reporting, though it is secondary to the maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.