This release appears usable and reasonably transparent: it is not deprecated, is stable, has a clear GPL-3.0-or-later declaration, a linked non-archived organization-owned repository, a changelog, and recent releases. The main concerns are limited demonstrated maintenance capacity—only one commit from one contributor in the last three months—along with no security scanning or security policy and a workflow granting top-level write permissions. The package is also small and newly established, so the lack of packaged tests and low repository popularity are meaningful but not by themselves disqualifying; dependency adoption is reasonable for a thin Moodle plugin.
70%
Total Score
63
100
83
80
The package is only 78 days old with four releases and a median release interval of about 34 days. This demonstrates ongoing publishing activity, but the short history limits evidence of long-term maturity.
All recent commit activity is concentrated in one contributor, creating a thin observed maintenance base. Organization backing provides some ability to hand maintenance off, but no second active contributor is shown.
Only one commit by one active maintainer is recorded in the last three months. The recent push is positive, but the low activity level leaves maintenance continuity uncertain.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently negative for a small plugin, but it provides little evidence of an active support community.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, and the organization-owned context means these counts are a limited concern rather than a standalone abandonment verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 4.5.* || 5.0.* || 5.1.* || 5.2.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.