A small maintenance footprint and no security policy leave some uncertainty for long-term support. The package is clearly identified, licensed, tested, documented, and not deprecated or archived.
67%
Total Score
50
100
92
50
The package has existed since August 2018 with 28 releases, but only 1 release in the last 12 months, indicating slower recent delivery rather than abandonment.
There were 0 commits and 0 active maintainers in the last 3 months, which is a meaningful maintenance concern, although the repository was pushed recently and a release was published in April 2026.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed without high- or medium-severity findings, and one scopes permissions read-only; however, all 3 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0-alpha.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.