It has an MIT license, release notes, a changelog, and only one runtime dependency. The missing security policy and limited project transparency make long-term support harder to establish.
45%
Total Score
33
100
67
83
The package has only two releases, with the latest published in January 2023 and no releases in the following 12 months, indicating an extended maintenance gap.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository is owned by an individual user rather than an organization, so the single registry maintainer provides limited visible backing for continuity.
There are no open issues or pull requests and no recent issue or pull-request activity, leaving no evidence of an active maintenance community.
The repository name does not match the package name and its README does not mention the package, so the link may not clearly establish that this repository is the package's source.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.