The license text needs clarification, and the automation has weak pinning and broad write access. The repository is not archived and includes usable documentation, but its maintenance record is too limited to support strong confidence.
58%
Total Score
75
100
86
67
The manifest declares GPL-3.0-or-later, while the artifact license file is detected as AGPL-3.0; the release is licensed, but the mismatch reduces transparency.
Only one release is recorded, with no established release cadence; this may reflect a newly mirrored package, but it provides little evidence of release maturity.
The repository has no commits and no active maintainers in the last 3 months, leaving current maintenance capacity un demonstrated.
No repository security policy is present, which weakens vulnerability-reporting transparency for a plugin that handles uploaded files.
The sole workflow gives top-level write permissions and both action references are unpinned. A high-confidence template-injection finding is present, but there is no untrusted trigger or checkout count tying it to an exploitable path, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 3.10.* || 3.11.* || 3.5.* || 3.6.* || 3.7.* || 3.8.* || 3.9.* || 4.0.* || 4.1.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.