The repository has no security scanning or policy, and its single registry maintainer limits transparency. Recent releases, a current source tree, and a clear MIT license provide useful counterweight, but verify the repository relationship before adoption.
57%
Total Score
50
100
83
83
Only one registry account has publishing access. Because the linked repository owner is a user rather than an organization, there is no provided organizational backing to offset this thin publishing base.
The registry namespace and repository owner differ, and the repository owner is an individual account rather than an organization, providing limited evidence of durable project backing.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful maintenance and abandonment concern.
The repository name does not match the package name and its README does not mention the package, so the linkage is not transparent and the package may be using an unrelated repository.
The repository has 0 stars and 0 forks and only 1 watcher, providing little independent evidence of sustained community use; popularity is supporting evidence rather than decisive proof.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.