This is a mature, actively published package with more than ten years of release history, 118 releases, a current stable version, a non-archived repository, and organization backing from Spicy Web. Its main concerns are limited recent development activity—only 2 commits in the last 3 months from one contributor—and the absence of repository security scanning, a security policy, and tests. Those gaps warrant monitoring and review before adoption, but the strong release cadence, documentation, changelog, licensing, and maintained repository make it a generally reasonable dependency.
78%
Total Score
80
100
89
90
The artifact has a README and changelog, and the repository also has a changelog and uses GitHub Releases. Tests are absent in both places, which is a modest transparency gap for a plugin with substantial source code.
All 2 recent commits came from one contributor, giving a 100% top-contributor share. This is a genuine continuity concern, although organization ownership provides some potential for handoff.
There were 2 commits in the last 3 months with 1 active maintainer. Recent work has not stopped, but the low volume suggests maintenance capacity may be constrained.
Composer is used as a build tool, but no security scanning tools are configured. The build tooling is positive, while the missing scanning reduces supply-chain transparency.
No repository security policy was found. This weakens vulnerability-reporting transparency, though it is a hygiene gap rather than evidence that the package is unmaintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
embed/embed Version ^4.4.10 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.