It includes a substantial README, changelog, repository tests, a matching source repository, and a clear MIT license. The workflow uses four unpinned actions, while maintenance and security practices remain unproven after a single release.
62%
Total Score
50
100
89
67
Only one registry account has publish access. That is a limited publishing base, and the user-owned project backing does not provide evidence of a broader maintenance team.
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational continuity to offset the single-maintainer and new-project concerns.
This is a new package with one release published less than a day ago, so there is not enough history to demonstrate sustained maintenance or long-term stability.
The repository shows zero commits and zero active maintainers in the last three months, but the package was only released less than a day ago, so this is mainly an absence of history rather than evidence of collapse.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency gap for a package with otherwise visible source and tests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.31 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.