Usable with caveats: it has a long release history, a current stable release, clear licensing, and organizational backing. However, the repository shows no commits or active maintainers in the last three months and has no tests or security scanning, so maintenance confidence is limited.
72%
Total Score
83
100
88
100
A README and changelog are present, and the repository uses GitHub Releases, but neither the package nor repository contains tests. For a plugin, this leaves behavior and regression coverage less transparent.
There were zero commits and zero active maintainers in the last three months. Although a current release and recent repository push provide some compensating evidence, the absence of recent development activity lowers maintenance confidence.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency and assurance gap, though it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verbb/base Version ^3.0.0 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
thunderer/shortcode Version ^0.7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.