Strong documentation, tests, and release notes make the package easier to adopt. Unpinned workflow actions and no security policy leave avoidable maintenance gaps.
62%
Total Score
50
81
50
The manifest declares a proprietary license, with no detected license text or license file. That creates a real licensing barrier for developers seeking an open-source dependency.
This is a 38-day-old package with only one release, so there is not enough release history to demonstrate sustained maintenance. Its recent first release is consistent with a new project rather than abandonment.
All recorded commits in the last three months came from one contributor, leaving no demonstrated backup maintainer. The repository owner is an individual, so there is no organizational backing shown to offset that concentration.
Only one commit was recorded in the last three months, with one active maintainer. For a package released 38 days ago this is limited evidence of continued maintenance, but it does not yet show a long-term collapse.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.