The organization-backed repository is clearly matched to the package and the release is licensed. Its small dependency footprint and clean install behavior help, but there is not yet enough history to establish durability.
68%
Total Score
83
100
88
88
The package is less than one day old with only two releases, so there is no meaningful track record of maintenance or compatibility yet.
There were no commits from active maintainers in the prior three months. Because the repository is less than one day old, this mainly shows that maintenance history has not yet been established rather than proving abandonment.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest transparency and maintenance-process gap.
The repository has no security policy, so users have no documented reporting path or disclosure process; this is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.