Usable with caveats: it is a mature, licensed plugin backed by an organization and has a current stable release. However, repository commits and issue activity have been absent for three months, and the project has no tests or automated security scanning.
68%
Total Score
75
100
81
100
The package includes a README and changelog, but neither the artifact nor repository contains tests. For a plugin that changes content-management behavior, the lack of visible tests is a meaningful maintenance and regression concern.
The package has existed for about 7 years and has 23 releases, but only one release was published in the last 12 months. Its long history and latest release partly compensate for the slower recent cadence, but maintenance appears less active.
The repository recorded zero commits and zero active maintainers in the last three months. The current release and recent repository push provide some compensation, but the lack of sustained commit activity raises abandonment and maintenance concerns.
There are three open issues, but no issues or pull requests were opened or closed in the last month. This suggests limited recent project interaction, although the small issue backlog is not severe by itself.
Composer is used for builds, but no security-scanning tools are configured. This is a transparency and maintenance gap, though it is not by itself evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verbb/base Version ^3.0.0 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.