The release includes specific fixes and updated dependencies, and the repository has tests, a changelog, and security scanning. Workflow review found no dangerous findings, though action references are unpinned.
82%
Total Score
83
100
94
75
One contributor made 90% of the 20 recent commits, creating concentration risk, though a second contributor remains active and the repository is organization-owned.
The repository name does not exactly match the package name and its README does not mention the package, so package-to-repository identity is less explicit; the shared organization provides some context but does not fully remove the gap.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear despite its security scanning tools.
Both workflows were analyzed successfully with no audit findings or untrusted checkout and script-injection patterns. All four action references are unpinned, which is a workflow hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.8.0 | — | — |
yiisoft/yii2 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.