Documentation is extensive and the release includes detailed notes. The organization provides useful continuity, but this beta should be pinned and monitored for updates.
72%
Total Score
80
100
88
88
One contributor made all 50 commits in the last three months, creating a concentrated maintenance dependency. Organization ownership provides some continuity, but no second recently active contributor is shown.
The repository recorded 50 commits in the last three months, showing strong recent activity. All activity came from one active maintainer, which limits the breadth of observed maintenance capacity.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest transparency gap rather than evidence of unsafe code.
This release is a beta while the latest version is stable 3.2.10, so the assessed version carries more change and compatibility risk than the project's normal stable line.
The single workflow was fully analyzed with no high-confidence audit findings, unsafe untrusted checkouts, or script injections. Both action references are unpinned, however, which leaves the build exposed to changes in referenced actions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verbb/base Version ^3.0.0 | — | — |
craftcms/cms Version ^5.9.0 | — | — |
ueberdosis/tiptap-php Version ^1.0 | — | — |
yii2mod/yii2-array-query Version ^1.4 | — | — |
nystudio107/craft-plugin-vite Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.