A license file, tests, and release notes improve transparency. Composer post-install and post-update hooks, plus no documented security policy or scanning tools, merit a local review before deployment.
82%
Total Score
100
94
50
Composer post-install and post-update hooks run during dependency operations. They are not inherently unsafe, but they add execution-time supply-chain exposure and warrant review.
Composer is used as a build tool, but no security scanning tools are reported. That is a modest transparency gap, not evidence of abandonment.
The repository has no documented security policy, leaving vulnerability-reporting and response expectations unclear for a production plugin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0|^5.0.0 | — | — |
nesbot/carbon Version ^1.22.1|^2.19|^3.0.0 | — | — |
symfony/finder Version ^2.8|^3.0|^4.0|^5.0|^6.0|^7.0 | — | — |
rlanvin/php-rrule Version ^1.6.0|^2.0.0 | — | — |
symfony/filesystem Version ^2.8|^3.0|^4.0|^5.0|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.