The package includes a clear README, release notes, tests, changelog, MIT licensing, and a small runtime dependency set. Its workflow uses read-only permissions but leaves all six action references unpinned, so future workflow changes are less reproducible.
68%
Total Score
100
100
86
50
This is the first release, published today, so there is no track record for release consistency or long-term maintenance. The included release notes provide useful transparency but do not establish maturity.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest repository hygiene gap, not a standalone dependency decision blocker.
The repository has no security policy. For a newly published package this reduces disclosure transparency, though the absence alone does not show an active security problem.
The single workflow was fully analyzed, uses read-only permissions, and has no reported high- or medium-confidence findings. All six action references are unpinned, which weakens build reproducibility and leaves future action changes uncontrolled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.0 | ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.