The source is clearly tied to the package, includes a README, changelog, tests, release notes, and a security policy. Recent repository and issue activity are absent, and all seven workflow actions are unpinned; pin 5.0.14 while maintenance resumes.
65%
Total Score
67
100
88
83
The package has 179 releases since July 2020, but only 2 releases in the last 12 months, indicating a slower current cadence for an otherwise mature project.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, a meaningful sign of currently quiet maintenance despite the recent release and push evidence.
There were 0 new or closed issues and 0 merged pull requests in the last month, with 30 open issues; this suggests limited recent issue-management activity.
The repository uses Make and Composer, but no security scanning tools were detected, leaving a modest security-process gap.
All 3 workflows were analyzed with no trigger-and-sink findings or auditor findings, and permissions are scoped in some jobs. However, all 7 action references are unpinned, weakening build reproducibility and update safety.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10122 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. nystudio107/craft-retour is vulnerable to Cross-Site Scripting in versions 4.0.0 - 4.1.12 and 3.0.0 - 3.2.11. | 3.0.0 - 3.2.114.0.0 - 4.1.12 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^8.2 || ^9.0 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
nystudio107/craft-plugin-vite Version ^5.0.0 | — | — |
jean85/pretty-package-versions Version ^1.5 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.