The package is licensed, documented, and has a lightweight dependency profile. Its workflows show no dangerous audit findings, but unpinned actions and no security policy leave preventable maintenance and supply-chain gaps.
58%
Total Score
83
100
88
75
The package has 17 releases since October 2017, but it had no releases in the last 12 months; this indicates a release gap that matters alongside the inactive repository.
There were zero commits and zero active maintainers in the last three months, with the last push more than two years ago; this is a meaningful abandonment risk even for a small stable plugin.
The repository uses Composer build tooling, but no security scanning tools are reported, leaving a modest hygiene gap.
No security policy is present in the repository, so users have no documented vulnerability-reporting path.
Both workflows were analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and permissions are scoped or read-only. However, both of the two action references are unpinned, which is a preventable supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0|^5.0.0-alpha | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.