Healthy and usable, with limited track record. It has a complete, tested package, clear documentation, active recent development, and balanced contributor activity, but it is only four days old with one release and lacks a security policy.
78%
Total Score
83
100
88
80
The package and repository are owned by the same individual account, which aligns ownership but provides less organizational continuity than an established organization-backed project.
This is a very new package, released four days ago with only one release, so its long-term maintenance and compatibility record are not yet established.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for future users and maintainers.
The workflow does not declare top-level token permissions, so its GitHub Actions permissions are less explicit than recommended.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.