The source project has practical maintenance evidence, including tests, a changelog, and recent commits. The main limitations are a single active contributor and one unpinned workflow action, while organization ownership provides some continuity.
76%
Total Score
83
92
67
The package is young, with two releases over about six months and roughly 111 days between releases. This is limited maturity evidence, but it does not indicate abandonment because the latest release is recent.
All 8 recent commits came from one contributor, creating concentration risk. Organization ownership provides some ability to hand maintenance to another person, partly compensating for that weakness.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, but not evidence that the package is unsafe to use.
The only workflow was fully analyzed with no audit findings, no untrusted checkout, and job-level permissions; however, its sole action reference is unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.