Tests and a clear README make the package easier to evaluate and maintain. Its single published release and no commits in the last three months leave maintenance continuity uncertain, while workflow permissions and unpinned actions add hygiene concerns.
60%
Total Score
75
100
88
75
Only one release is recorded, published 96 days ago, so there is little release history to demonstrate sustained maintenance or compatibility work.
There were zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance after publication.
Composer and Phing build tooling are present, but no security scanning tooling was detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, reducing clarity about vulnerability reporting and response for a package intended for Moodle deployments.
The only workflow gives top-level write permissions and uses both actions without pinning, while the high-confidence template-injection finding is hygiene rather than a demonstrated dangerous trigger-and-sink path.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 3.9.* || 3.10.* || 3.11.* || 4.0.* || 4.1.* || 4.2.* || 4.3.* || 4.4.* || 4.5.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.