The release cadence is slow, and the repository shows no commits or active maintainers in the last three months. The project is small but clearly matched to the package, with a current release, documentation, and no deprecation or workflow audit findings.
68%
Total Score
75
100
83
50
The package has six releases over about 3 years and 1 release in the last 12 months, with a median interval of about 9 months. The latest release is recent, but the slow cadence limits evidence of sustained maintenance.
There were no commits and no active maintainers in the last three months. Although a release was published during that period, the lack of ongoing repository activity raises maintenance risk.
The repository has 1 star, 0 forks, and 1 watcher. This is weak supporting evidence of adoption, though popularity alone does not establish poor maintenance.
The repository uses Composer, which fits the package ecosystem, but no security scanning tools were detected. That is a modest transparency and hygiene gap.
No repository security policy was found. For a small CMS plugin this is not disqualifying, but it provides little documented guidance for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.