This release appears to be a healthy dependency for its ecosystem: it is actively released, uses a stable major version, is not deprecated, has a clear AGPL license, substantial package and repository documentation, repository tests, and an organization-backed source repository. Recent activity is distributed across four maintainers rather than concentrated in one person, and the repository matches and explicitly references the package. The main concerns are a sizable open issue backlog, absence of a repository security policy and dedicated security scanning, and limited workflow permission hardening, but these are hygiene and process gaps rather than evidence of abandonment or an unfit release.
84%
Total Score
90
100
94
70
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
civicrm/civicrm-core Version >=5.76 | — | — |
civicrm/civicrm-packages Version >=5.76 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.