It has a clear MIT license, tests, a detailed README, and a matching repository with a release note. The lack of a security policy and limited observed activity make its long-term maintenance record unproven.
65%
Total Score
50
79
75
The package is only 0 days old, with five releases published within roughly 14 hours. This shows active initial publishing but provides no meaningful long-term release history.
There were no commits or active maintainers in the preceding 3 months, although the repository was pushed recently and two pull requests were merged in the last month. The short observed history limits confidence in sustained maintenance.
The repository uses Composer build tooling, but no security-scanning tool was detected. The build setup is present, while security-process transparency is limited.
The repository has no security policy. That is a transparency and maintenance gap for a package that integrates into a CMS, though it is not evidence that the package is unsafe.
Version v0.1.4 is a pre-1.0 release, so its API and behavior may still change substantially. It is not marked as a prerelease, which provides a small compensating signal but does not establish maturity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.