The project is newly published, so long-term maintenance is not yet demonstrated. It has clear licensing, documentation, tests in the repository, and a matching source project; workflow permissions and unpinned actions merit routine review.
78%
Total Score
83
100
83
75
One registry account, D3 Creative, has publish access. A single publisher is a limited resilience signal, though it is consistent with the matching source project and does not by itself indicate abandonment.
The package is extremely new, with only two releases published on the same day, so there is not enough history to establish sustained maintenance.
The repository currently has zero stars, forks, and watchers. This is limited supporting evidence, but popularity alone does not determine health for a newly published package.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing the transparency of vulnerability reporting and maintenance expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.34 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.