The package has clear documentation, a matching repository, and a permissive license. Its small user base and no commits or issue progress since July 2024 make long-term maintenance less reassuring.
62%
Total Score
50
100
83
75
The package has seven releases over roughly five years, but none in the last 12 months; the latest release was in July 2024. This suggests maintenance has stopped or slowed substantially.
There were zero commits and zero active maintainers in the last three months, consistent with the last push occurring in July 2024. This is the strongest maintenance concern for a dependency.
Five issues remain open, with no new or closed issues and no pull-request activity in the last month. This adds to the evidence of limited recent project attention.
The repository has only 2 stars and 4 forks, showing limited adoption. Popularity is supporting evidence rather than a decisive health measure, but it provides little reassurance about ongoing support.
Composer is used as the build tool, but no security scanning tools are present. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version 3.* | 4.* | 5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.