This release appears healthy and reasonably safe to depend on: it has a matching, active source repository, frequent recent releases, substantial recent commit activity from two contributors, tests in the repository, a changelog, a security policy, and read-only workflow permissions. The main limitations are that the project is only 36 days old, has no observed adoption signals, relies on a single registry publisher, and has no automated security-scanning tool reported; these warrant monitoring but do not indicate abandonment or an immediate dependency-health concern.
82%
Total Score
70
100
83
100
Only one account has registry publish access, which creates publishing concentration for a user-owned project. However, registry access reflects administrative rights rather than actual maintenance, and repository activity shows a second active contributor.
The repository is owned by the user account goldnead rather than an organization, so there is no organizational handoff capacity to compensate for maintainer concentration. Actual repository activity from two contributors nevertheless provides current maintenance evidence.
The package is young at 36 days but has 10 releases in the last 12 months, with a median interval of about 2.3 days. This demonstrates active iteration, though the short history limits evidence of long-term maintenance.
There are no open issues and one open pull request, but no issues or pull requests were merged in the last month. With 53 recent commits, the lack of issue activity is not enough to indicate abandonment, though it leaves limited evidence of user-driven maintenance.
The repository has zero stars, forks, and watchers, so there is no external adoption evidence. Given the package's 36-day age, this is a maturity limitation rather than a severe health failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
laravel/framework Version ^12.40|^13.0 | — | — |
goldnead/statamic-brand-context Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.