Usable with caveats: the release is well documented, licensed, tested, and backed by a matching repository, but it is brand new and has no established commit or community track record yet.
62%
Total Score
75
100
83
90
One registry maintainer is consistent with the individually owned repository, but it also creates a single-person continuity risk for a project with no established activity history.
Seven releases appeared within the first day, showing active initial development but no meaningful long-term release history; the unusually short history limits confidence in durability.
The repository has zero commits and zero active maintainers in the collected three-month window. Because the project is only hours old, this is partly explained by its age, but it leaves maintenance capacity and continuity unproven.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap, not a severe risk by itself.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.27 | — | — |
symfony/yaml Version ^7.0 || ^8.0 | — | — |
league/commonmark Version ^2.4 | — | — |
symfony/html-sanitizer Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.