The repository is active, with a recent release, tests, release notes, and two active contributors. Install-time scripts, no security policy, and the repository/package naming mismatch add smaller concerns.
55%
Total Score
100
79
50
Packagist marks the entire package abandoned and names solspace/craft-calendar as its replacement, making continued dependency use a meaningful lifecycle risk despite the active source repository.
The package runs post-install and post-update Composer scripts, which increase install-time behavior and review requirements compared with a package without lifecycle hooks.
The repository name does not match the package name and its README does not mention the package, so the package-to-source relationship is less transparent even though the owner matches.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a plugin that contains substantial application code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0|^5.0.0 | — | — |
nesbot/carbon Version ^1.22.1|^2.19|^3.0.0 | — | — |
symfony/finder Version ^2.8|^3.0|^4.0|^5.0|^6.0|^7.0 | — | — |
rlanvin/php-rrule Version ^1.6.0|^2.0.0 | — | — |
symfony/filesystem Version ^2.8|^3.0|^4.0|^5.0|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.