Easily add modules to your pages
82%
Total Score
healthy
Healthy overall, supported by frequent releases and active source maintenance.
The manifest declares a proprietary license, while the artifact contains a detected MIT license file that the declaration does not cover. The package is licensed, but the mismatch requires clarification.
The registry namespace and repository are owned by the same individual account, so the project does not show organization backing that would offset concentrated maintenance.
Four contributors were active in the last 3 months, but one contributor made about 88% of the 51 commits. That concentration leaves meaningful continuity risk for this individually owned project.
The repository uses Composer for builds, but no security scanning tooling was detected. The missing scanning is a modest transparency gap rather than evidence of abandonment.
The linked repository has no security policy. This weakens the documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/cms Version ~5.0 | — | — |
getkirby/composer-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.