A plugin for Kirby 3 CMS to add modification timestamps to css and js files
68%
Total Score
50
100
88
88
A substantial README documents the plugin's behavior, limitations, installation, and URL-handling cases. Tests and a changelog are absent, which reduces validation and release transparency for a package that modifies generated asset URLs.
The source repository is owned by a personal user account rather than an organization, so the single-publisher context provides limited evidence of organizational continuity.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although recent registry releases provide some compensating evidence, the absence of recent source activity is a meaningful maintenance and abandonment concern.
Composer is used as a build/package tool, but no security scanning tools are configured. For this small PHP plugin the missing scanning is a hygiene gap rather than evidence of unfitness, but it weakens assurance.
No repository security policy was found, leaving disclosure and response expectations undocumented. This is a transparency gap, though the package's small scope and lack of reported issue backlog partly limit its significance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
getkirby/composer-installer Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.