The clear MIT license, README, and small runtime dependency set improve transparency and integration. Maintenance evidence is weak: the last registry release was over seven years ago, repository activity stopped nearly six years ago, and three issues remain open without recent resolution.
42%
Total Score
50
100
78
83
Only two releases were published, with the latest over seven years ago and no releases in the last 12 months. That long gap is strong evidence of abandonment risk for a plugin dependency.
A single registry maintainer provides limited publishing redundancy. The small package scope makes this less severe, but it still increases continuity risk.
The linked repository is owned by an individual rather than an organization, so the single-maintainer continuity concern is not offset by visible organizational backing.
Three issues and two pull requests remain open, with no issues or pull requests opened or closed in the last month. Combined with the old last release, this supports a meaningful abandonment concern.
The repository has zero stars and two forks. Popularity is only supporting evidence, but these low counts provide little external adoption or maintenance confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.