The focused codebase is clearly tied to an organization and has a license, release notes, dependency automation, and a matching repository. Its limited adoption, absent recent commit activity, missing security policy, and workflow hygiene issue reduce confidence in long-term upkeep.
58%
Total Score
67
100
94
67
Only one release exists, published about 3 years ago, with no releases in the last 12 months. That is meaningful evidence of limited ongoing maintenance for a plugin dependency.
There were no commits and no active maintainers in the last 3 months. Combined with the single-release history, this indicates weak evidence of active maintenance.
There were no issues or pull requests opened or merged in the last month, while one issue and three pull requests remain open. This suggests limited recent project responsiveness.
No security policy is present in the repository. That is a transparency gap for a plugin handling API credentials and messaging services.
The sole workflow uses a pull_request_target trigger, top-level write permissions, and an unpinned action; the high-confidence bot-conditions finding adds workflow hygiene concern. No untrusted checkout or script-injection sink was found, so this is not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sms77/api Version ^2.3.0 | — | — |
craftcms/cms Version ^3.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.