The package is licensed, has a matching repository, and is backed by an organization with a recent release. Its prerelease status, one release in the last year, no commits in three months, and unpinned workflow actions warrant caution.
65%
Total Score
75
81
100
The package has 49 releases since January 2018, but only one release in the last 12 months despite a historical median interval of about 26 days. That recent slowdown is a maintenance concern, although a release was published on May 30, 2026.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release provides some evidence of activity, but the current lack of development activity increases abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance hygiene gap rather than evidence that the package is unsafe.
Version 6.0.0-alpha.1 is explicitly a prerelease, so compatibility and behavior may still change. The package has a long release history, which partly offsets the maturity concern.
Both workflows were analyzed cleanly with no reported audit findings or untrusted checkout and script-injection sinks. However, both action references are unpinned, leaving workflow dependencies less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^6.0.0-alpha.5 | — | — |
giggsey/locale Version ^2.0.0 | — | — |
league/iso3166 Version ^3.0 | — | — |
maxh/php-nominatim Version ^2.0 | — | — |
craftcms/yii2-adapter Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.