Usable with caveats: the package is actively released, licensed, backed by an organization, and has a current source repository. Prefer a stable release if available because this version is an alpha and recent repository work comes from only one contributor.
72%
Total Score
67
88
100
All 4 recent commits came from one contributor, creating a concentrated maintenance dependency. The organization backing provides some ability to hand work off, but no second active contributor is shown.
The repository had 4 commits in the last 3 months, so activity has not stopped. However, the volume is modest for a package with ongoing releases.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a transparency and process gap rather than evidence that the package is unsafe.
This release is a prerelease, and 35% of recent releases were prereleases. The stable major version and frequent releases provide some maturity context, but alpha software carries additional compatibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^4.0|^5.74|^6.26 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.