Healthy and reasonable to adopt, with some maintenance and workflow caveats. It has frequent recent releases, active repository work, comprehensive tests, and clear licensing, but all recent commits come from one contributor and the project remains pre-1.0.
78%
Total Score
63
100
94
70
One workflow uses pull_request_target, which warrants review because it can run with elevated repository context, but no untrusted checkout or script-injection patterns were detected.
The repository is owned by the same individual namespace as the package, so the single-maintainer concentration is not offset by organizational backing.
One contributor made 100% of the 22 commits in the last three months, creating a meaningful continuity risk if that maintainer becomes unavailable.
There were 22 commits in the last three months, demonstrating ongoing maintenance, but all were made by one active maintainer.
No security policy is present, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.74.0 || ^6.20.3 | — | — |
rlanvin/php-rrule Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.