The repository includes tests, release notes, and a clear license file. All four workflow actions are unpinned, and no security policy is published.
60%
Total Score
75
79
50
The package has a substantial history with 33 releases since April 2019, but it has had no registry release in about 17 months. That weakens evidence of current maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly 17-month release gap. This is the main abandonment concern despite the repository remaining unarchived.
Composer build tooling is present, but no security scanning tool was detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
No security policy was found in the linked repository, leaving the vulnerability-reporting process unclear.
The assessed release is marked stable and not a prerelease, but the registry reports latest_version as 4.2.0 while this assessment targets 5.2.0. That version metadata mismatch reduces confidence.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0 | — | — |
aws/aws-sdk-php Version ^3.0 | — | — |
putyourlightson/craft-blitz Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.