The package is documented and licensed, and its repository clearly matches the package. It has only two runtime dependencies and no install-time scripts, keeping adoption straightforward.
78%
Total Score
75
100
88
75
The package has existed since April 2018 but has only six releases, with a median interval of about 438 days. One release in the last 12 months and the December 2025 latest release show ongoing availability, but maintenance is infrequent.
The repository had zero commits and zero active maintainers in the last three months. Although the recent release and push provide some compensating evidence, the lack of current development activity is a maintenance concern.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.