Clear licensing, tests, release notes, and organization backing support adoption. The project is young, remains prerelease, and shows no commits in the last three months; unpinned workflow actions and no security policy add maintenance overhead.
63%
Total Score
75
75
50
Six releases in about five and a half months show active initial development, but the very young package and same-day median release interval provide limited evidence of mature long-term maintenance.
The repository shows zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern despite the recent release history.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The linked repository has no security policy, reducing clarity about vulnerability reporting and response practices.
The assessed release is a beta and all recent releases are prereleases, so consumers should expect possible breaking changes and less-established behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
civicrm/civicrm-core Version >=6.8 | — | — |
civicrm/civicrm-packages Version >=6.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.