This is a young but currently usable and reasonably transparent Moodle plugin release. It has a stable, non-prerelease version, recent publication and repository activity, a README, changelog, tests, a complete-looking 33-file tree, an explicit GPL-3.0-or-later license, and no deprecation or archival indicators. The main concerns are limited observed maintenance capacity—only one commit from one contributor in the last three months—along with no repository security policy, no security scanning tools, and a workflow with top-level write permissions. Organization backing and the repository's matching name reduce, but do not eliminate, the maintenance and transparency risks.
78%
Total Score
67
100
83
80
The package is only 78 days old with four releases and a median interval of about 34 days, showing active initial publishing but limited long-term maturity evidence.
All three-month commit activity is concentrated in one contributor. The organization-owned repository provides some handoff potential, but no second active contributor is shown by this signal.
Only one commit by one active maintainer was observed during the last three months, which is weak evidence of ongoing maintenance despite the recent push and release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of adoption signals provides no external maturity reassurance.
Composer is used as a build tool, which is appropriate for the package, but no security scanning tools are configured; the missing scanning is a modest transparency and assurance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
moodle/moodle Version 4.5.* || 5.0.* || 5.1.* || 5.2.* | — | — |
composer/installers Version ~1.0 || ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.