Usable with caveats: the package is actively released, backed by an organization, and has a matching repository with documentation, tests, and a license file. Recent repository activity is very light and concentrated in one contributor, so maintenance continuity should be monitored.
72%
Total Score
70
50
94
100
Six runtime dependencies, including Craft CMS and related plugins, create a meaningful compatibility surface but are reasonable for a Craft CMS integration package.
All two recent commits came from one contributor, concentrating maintenance capacity; organization backing provides some ability to hand work off but does not remove the observed continuity risk.
Only two commits were recorded in the last three months, which is light activity for an established package even though the latest release is current.
There is some recent issue intake, but nine issues remain open and none were closed in the last month, indicating limited visible follow-through.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and security-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
verbb/base Version ^3.0.0 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
wa72/htmlpagedom Version ^2.0 || ^3.0 | — | — |
mistralys/text-diff Version ^2.0 | — | — |
nystudio107/craft-plugin-vite Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.