The project has a clear package structure, tests, documentation, and no install-time scripts. Its organization backing and active release cadence provide useful continuity.
82%
Total Score
100
100
89
75
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear for a package used in CMS installations.
This assessed release is a beta while the latest version is a stable 5.13.3, so it carries more compatibility risk than the project's stable release line.
Both workflows were analyzed with no audit findings, no untrusted checkouts, and no script-injection paths; however, all four action references are unpinned, weakening build reproducibility and update safety.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10165 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. putyourlightson/craft-blitz is vulnerable to Malicious Code in versions 3.11.1 - 3.14.0 and 4.0.0 - 4.11.2. | 3.11.1 - 3.14.04.0.0 - 4.11.2 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.2.1 | — | — |
cpliakas/git-wrapper Version >=1.7.0 | — | — |
putyourlightson/craft-log-to-file Version ^1.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.