This is a well-scaffolded, clearly licensed Craft CMS plugin with an organization-owned repository, matching package/repository identity, tests, changelog, and no registry deprecation or install-time lifecycle scripts. However, the release is brand new, with only one release and no demonstrated maintenance history, and the repository has no observed popularity or issue activity; the absent security policy and incomplete workflow permission declarations are additional transparency and CI-hygiene gaps. It is reasonable to evaluate for adoption in a controlled setting, but the limited track record warrants caution until subsequent releases and maintenance activity establish durability.
68%
Total Score
83
100
83
80
Only one release exists and the package is 0 days old, so there is no demonstrated release continuity or maintenance track record yet.
There are no issues or pull requests and no activity in the last month; combined with the package's age of 0 days, this is mainly an unproven-maintenance gap rather than evidence of abandonment.
The repository has zero stars, forks, and watchers. For a newly published package this is understandable, but it provides no external adoption or durability evidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
No repository security policy was detected, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.