The package is small, clearly scoped, and easy to identify in its matching source repository. MIT licensing and a simple dependency profile help, but the lack of security tooling and policy leaves little evidence of ongoing project oversight.
55%
Total Score
100
75
50
Only two releases were published, both in April 2020, with no releases in the following six years. That is substantial evidence of inactivity, although a narrowly scoped plugin may require few changes once stable.
Composer is used for the build, but no security scanning tools are present. This is a modest transparency and maintenance concern rather than a severe risk.
The repository is not archived, which preserves a path for maintenance, but its last push was on April 24, 2020 and reinforces the long release gap.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities. This is a minor transparency gap for a package that integrates with a CMS.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.