The package includes a matching repository, MIT licensing, a repository changelog, and release notes for this version. Its small audience and lack of a security policy limit assurance, while the sole workflow uses an unpinned action.
67%
Total Score
50
100
93
75
There were zero commits and zero active maintainers in the last three months. Although a release was published during that period, the lack of observed development activity raises maintenance risk.
Composer build tooling is present, but no security scanning tools were detected. For a small plugin this is a hygiene gap rather than evidence of abandonment.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, and it scopes permissions at job level. Its one action reference is unpinned, which is a supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.