The repository remains organized, licensed, tested, and backed by an organization, but issue activity is dormant. Nine workflow actions are unpinned and no security policy is provided, adding release and maintenance concerns.
43%
Total Score
63
100
88
67
The package has had no registry release in nearly seven years, despite eight releases overall, which is a substantial abandonment concern for a framework plugin.
The repository recorded zero commits and zero active maintainers in the last three months, weakening the evidence that bugs and compatibility changes are being maintained.
There are 13 open issues but no new or closed issues and no pull-request activity in the last month, indicating that reported maintenance needs are not being actively handled.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
All four workflows were analyzed with no dangerous sinks or high-confidence findings, but all nine action references are unpinned; this is a supply-chain hygiene weakness rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^8.1|^9.0 | — | — |
craftcms/cms Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.