The repository includes tests and a changelog, and the package has no install-time scripts. Its single workflow has no dangerous findings, but one action is unpinned and no security policy is present.
61%
Total Score
50
70
75
The package was first released 0 days ago and has four releases on the same day, so there is not yet enough history to demonstrate sustained maintenance.
The repository shows 0 commits and 0 active maintainers in the last 3 months, but the package itself is 0 days old, so this reflects limited history rather than demonstrated abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The linked repository has no security policy, making vulnerability reporting and response expectations unclear for a package with content-editing functionality.
v1.0.0 is a stable major release, but 75% of recent releases were prereleases, indicating a very early and still-changing project.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version ^0.8.1 | — | — |
craftcms/cms Version ^5.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.