The package is licensed and its repository matches the package, includes documentation, and has a documented release workflow. The workflow still uses an unpinned action and the project lacks a security policy, leaving avoidable maintenance and supply-chain hygiene gaps.
64%
Total Score
50
93
75
This is the only release, published about 5 months and 12 days ago, so there is limited evidence of sustained release maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which weakens evidence that issues and compatibility changes will receive attention.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no dangerous findings, job-level permissions, and no untrusted checkout or script-injection paths. Its one action reference is unpinned, which is a minor supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
samuelreichor/craft-co-pilot Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.