Documentation, tests, licensing, and frequent releases provide a solid foundation. Pin the three workflow actions before relying on automated builds.
72%
Total Score
67
100
100
67
The package and repository are owned by the same individual user account, so there is no organization backing to offset the concentrated maintainer base.
All 70 recent commits came from one contributor, creating a meaningful continuity risk if that maintainer becomes unavailable.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
The only workflow was fully analyzed with no detected audit findings, but all three referenced actions are unpinned, so build inputs can change without a repository commit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
miko/laravel-latte Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.