Optimize your site for LLMs
78%
Total Score
healthy
Active release cadence is offset by a single-contributor project and six unpinned workflow actions.
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
One contributor made all 62 commits in the last three months, leaving the project highly dependent on a single maintainer and increasing continuity risk.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and preventive-maintenance gap, not evidence of a defect.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings, and permissions are scoped in two workflows. However, all six action references are unpinned, weakening build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
amphp/http-client Version ^5.3 | — | — |
league/html-to-markdown Version ^5.1 | — | — |
paquettg/php-html-parser Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.