The package is clearly identified, MIT-licensed, and includes a usable README and changelog. Its small dependency footprint and lack of install scripts reduce adoption friction, but the long inactivity remains a serious concern.
45%
Total Score
25
100
79
75
The latest release was published in August 2020, with no releases in the last 12 months. This long gap materially raises abandonment risk despite a history of five releases.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing no activity since August 2020.
Only one registry publishing maintainer is listed, leaving limited observable publishing capacity. This is a secondary concern because the repository is correctly identified and owned by the same individual.
Composer is used as the build tool, but no security scanning tools are present. This is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported. The absence is more concerning alongside the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.