The package includes a README, tests, a focused runtime dependency, and no install-time scripts. Its workflows have high-confidence bot-condition concerns, broad write permissions, and all nine actions are unpinned.
45%
Total Score
33
100
72
50
The package has only three releases, all concentrated in January 2025, with no releases in the following 20 months. That limited and stopped release history raises abandonment risk.
There were no commits and no active maintainers in the last three months, consistent with roughly 20 months since the last recorded push. This is strong evidence of stalled maintenance.
All four workflows were analyzed, but the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. All nine action references are unpinned, and three workflows grant top-level write permissions, increasing workflow supply-chain and maintenance risk.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to offset the thin maintenance activity.
There were no new or closed issues or pull requests in the last month, while one pull request remains open. This provides little evidence of current maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.