Usable with caveats: it has a long release history, a matching repository, tests, licensing, and a release for v3.0.0. Recent repository activity is absent, popularity is very low, and workflow permissions are not explicitly restricted, so maintenance and CI hygiene warrant review before adopting it.
68%
Total Score
75
100
89
75
One of five workflows uses pull_request_target, which can require careful review because it runs with elevated event context. No untrusted checkout or script-injection patterns were detected, limiting the concern.
The repository recorded 0 commits and 0 active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release history and March 2 repository push provide some counterevidence.
The repository has only 2 stars, 0 forks, and 0 watchers. Low popularity is supporting evidence rather than a verdict, but it means less visible community validation and fewer likely external maintainers.
Composer build tooling is present, but no repository security-scanning tool was detected. The absence of scanning is a hygiene gap rather than evidence that the package is unsafe.
All five analyzed workflows lack top-level permissions declarations. No workflow requests top-level write permissions, but explicit least-privilege settings would provide stronger CI safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ezsystems/ezplatform-admin-ui Version ^2.0@dev | — | — |
ezsystems/ezplatform-content-forms Version ^1.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.