Risky to adopt for a new project: the package has had no release or repository commit in about six years. It is clearly backed by a matching organization repository and has a license and README, but its maintenance appears effectively stopped.
45%
Total Score
50
100
78
88
The latest release was published about six years ago, with no releases in the last 12 months; only three releases exist overall. This is strong evidence of an unmaintained package, despite its earlier regular release spacing.
The repository has had no commits and no active maintainers in the last three months, consistent with the release gap. The repository is not archived, but there is no recent activity showing ongoing support.
There are no open issues or pull requests and no recent issue or pull-request activity. A clean tracker is mildly positive, but it does not demonstrate active maintenance when combined with the long release and commit gap.
The repository has only two stars and one fork. This is limited supporting evidence, not a decisive concern by itself, especially for a small specialized plugin, but it offers little community validation.
The repository uses Composer, but has no security scanning tools. The missing scanning is a modest transparency gap, while the absence of build complexity is not concerning for this small PHP plugin.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.