Clear documentation, tests, and a recent security-focused fix improve confidence. Limited security process and a thin publishing base reduce resilience if maintenance stops.
61%
Total Score
25
100
75
The repository recorded zero commits and zero active maintainers in the last three months. This is concerning alongside the project's stated search for a new maintainer, despite the recent release.
Only one account has registry publishing access, which creates continuity risk. The organization-owned project backing makes a short registry maintainer list less concerning than it would be for an ownerless project, but does not remove the single-publisher dependency.
The repository has no security policy. For a plugin that processes external media URLs and recently addressed injection-related issues, the lack of a documented reporting process is a meaningful transparency gap.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 9 action references are unpinned. That leaves avoidable build reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
embed/embed Version ^v4.4 | — | — |
craftcms/cms Version ^4.0 | ^5.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.