Documentation and release notes make integration clearer, while the repository has meaningful recent activity. Pin the six workflow actions; otherwise the evidence supports adopting this release.
78%
Total Score
75
100
94
100
Only one registry account can publish releases, which is a modest publishing concentration for an individual-owned project, though repository activity shows broader participation.
The registry namespace and repository are owned by the same individual account, providing clear ownership but no organizational handoff capacity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and vulnerability-monitoring gap.
The workflow uses read-only permissions and has no dangerous triggers, untrusted checkouts, or audit findings. However, all six action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
illuminate/console Version ^12.40|^13.0 | — | — |
illuminate/support Version ^12.40|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.