The project has no commits in the last three months and no security policy, limiting visible maintenance and disclosure practices. It is otherwise a small, clearly scoped plugin with a recent stable release, matching repository, license, README, and no install-time scripts.
72%
Total Score
75
100
88
67
The package has existed for about 3 years and 10 months, with four releases and one release in the last 12 months. The roughly 304-day median interval indicates slow but continuing maintenance rather than abandonment.
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent release compensates for some concern, the current lack of observed activity lowers maintenance confidence.
Composer is used for the build, but no security scanning tools are reported. For a small plugin this is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy or documented security-reporting path. This weakens vulnerability disclosure practices, though it does not by itself show the package is unsafe.
No GitHub Actions workflows were present, so the audit found no workflow vulnerabilities or unpinned actions. There is also no automation evidence to support build and release hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.