This is a healthy, mature release with a long history since 2018, 413 releases, 17 releases in the last 12 months, and a recent release, indicating active maintenance and stable delivery. The linked repository is not archived, is organization-owned, matches the package name, contains tests and a changelog, and shows two active contributors; its 393 stars and 66 forks provide supporting evidence of adoption. The main reservations are the absence of repository security scanning and a security policy, plus relatively light recent commit activity and some concentration in one contributor, although the organization backing and continued releases materially reduce abandonment risk. The package is suitable to depend on, subject to normal review of its proprietary licensing terms and runtime dependencies.
88%
Total Score
88
100
94
90
Two contributors were active in the last 3 months, but the top contributor made 75% of commits. This is a mild concentration risk, partly offset by the organization-owned repository and the second active contributor.
Composer build tooling is used, but no security scanning tools are detected. The build tooling is positive, while the missing scanning reduces supply-chain transparency and warrants caution.
The repository has no security policy. For a maintained package this is a genuine disclosure and maintenance-hygiene gap, though it is not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.