It has a clear MIT license, useful documentation, and a source repository that matches the package. The small project has no recent activity, security policy, or security scanning, making long-term maintenance uncertain.
42%
Total Score
50
69
50
The latest release was in December 2020, with no releases in the last 12 months. This long gap is strong evidence of abandonment risk for a package intended as an application integration.
Two issues remain open, with no new or closed issues and no pull-request activity in the last month. This supports the broader evidence of an inactive project.
The repository has only 3 stars and 2 forks. Popularity is supporting evidence rather than decisive, but these low counts provide little evidence of a broad maintainer or user community.
Composer is used as the build tool, but no security-scanning tooling is reported. This is a modest supply-chain hygiene gap, not evidence that the release is malicious.
The repository is not archived, which is reassuring, but its last push was in December 2020 and does not show active maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.