Clear documentation, a matching repository, and release notes improve adoption confidence. The project is less than a day old, has no recorded commits in the last three months, and uses five unpinned workflow actions, so its longer-term maintenance and build integrity remain unproven.
68%
Total Score
75
100
88
67
The package was first released less than a day ago and has five releases in that period. This shows active initial publishing but provides almost no evidence of sustained maintenance yet.
No commits or active maintainers were recorded during the last three months, which weakens evidence of ongoing maintenance. The repository was nevertheless pushed recently and merged 42 pull requests in the last month, so this is a concern about historical coverage rather than clear abandonment.
The repository uses Composer, but no security scanning tool was detected. That is a modest transparency and maintenance gap, not evidence that the code is unsafe.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a package that handles external provider credentials and content workflows.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts, injection findings, or other audit findings. However, all five referenced actions are unpinned, so their exact build inputs are not fixed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.30 | — | — |
symfony/yaml Version ^7.0 || ^8.0 | — | — |
guzzlehttp/psr7 Version ^2.6|^3.0 | — | — |
guzzlehttp/guzzle Version ^7.8|^8.0 | — | — |
league/commonmark Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.