It has an MIT license, a matching source repository, and a documented repository changelog. The single release and roughly 18 months without commits suggest limited maintenance, while an unpinned workflow action adds a smaller supply-chain hygiene concern.
57%
Total Score
33
50
71
67
The repository had zero commits and zero active maintainers during the last three months. Combined with the single-release history, this materially lowers confidence in active maintenance.
Seven runtime dependencies, including Craft CMS and several project-specific packages, create meaningful dependency surface area for a small package. The signal does not show that these dependencies are excessive or unmanaged.
Only one registry maintainer is listed. Because the repository owner is an individual rather than an organization, this represents a thin publishing base and modest continuity risk.
The registry namespace and repository owner match, but both belong to an individual account rather than an organization. This supports package identity while offering limited evidence of broader project backing.
This is the package's only release, published roughly 18 months ago, with no releases in the last 12 months. That limited history makes ongoing maintenance harder to establish.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0 | — | — |
symfony/process Version * | — | — |
panlatent/craft-enums Version dev-main | — | — |
panlatent/craft-attribute Version dev-main | — | — |
panlatent/craft-form-schema Version dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.