Documentation, tests, and release notes make the package easier to evaluate and maintain. However, it has only one release, no commits in the past three months, three unpinned workflow actions, and no security policy.
67%
Total Score
50
100
83
75
The package has only one release, published in January 2026, with no additional releases in the recorded history. This limits evidence of sustained maintenance but does not by itself indicate abandonment.
There were no commits and no active maintainers in the past three months. Combined with the single-release history, this is meaningful evidence that ongoing maintenance is not yet established.
The repository has 2 stars, 0 forks, and 0 watchers. This is weak supporting evidence of community adoption, although popularity is not required for a small, focused package.
The repository uses Composer, but no security scanning tools were detected. That is a modest build-hygiene gap rather than a severe dependency risk.
No security policy was found in the repository. For a package that adds application code and editor functionality, this reduces transparency around vulnerability reporting.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.