Usable with caveats: the package is licensed, stable, documented, and backed by a matching organization repository, but it has had no release or commit activity for more than three years. The absence of security scanning and a security policy adds maintenance risk for a plugin handling web integrations.
55%
Total Score
75
79
75
Only three releases were published, with none in the last 12 months; the latest release was more than three years ago. This suggests the package may be abandoned or no longer actively maintained.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last release. This is a meaningful maintenance and abandonment concern.
The repository uses Composer, but it has no security scanning tools. For a plugin integrating web push functionality, this is a transparency and maintenance gap, though it is not evidence of malicious behavior.
The linked repository is not archived, but it was last pushed more than three years ago. The unarchived status is reassuring, while the old activity still indicates possible abandonment.
No security policy is present in the repository, leaving no documented process for reporting or handling vulnerabilities. This lowers transparency for a package that integrates with an external web service.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.