Clear MIT licensing, useful documentation, and organization backing make the package easier to assess and integrate. The repository has no security policy or scanning, so ongoing maintenance requires extra care.
58%
Total Score
67
100
81
83
The latest registry release was published nearly six years ago, with no releases in the last 12 months. That is a substantial maintenance concern for a Craft CMS integration.
There were zero commits and zero active maintainers during the last three months. Combined with the old registry release, this points to a real abandonment risk.
There was no issue or pull-request activity in the last month, while 14 pull requests remain open. This suggests limited recent attention to contributions and fixes.
The repository uses Composer, which supports reproducible PHP builds, but it has no security scanning tools. That is a modest transparency and maintenance gap.
The linked repository is not archived, but its last push was more than three years ago. That keeps it available while still indicating limited recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0-RC1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.