This release appears healthy and reasonably safe to depend on from a maintenance and supply-chain transparency perspective. It is a young package, but it has released 10 times in 36 days, is on a stable major version, is not deprecated, has an active non-archived repository, and shows 49 commits from two active contributors in the last three months. The artifact is well-structured, includes a README, changelog, license file, and build workflows, while the absence of packaged tests is compensated by repository tests. The main concerns are the lack of a repository security policy, no configured security-scanning tool, and a workflow with top-level write permissions; these warrant review but do not indicate abandonment or make the package unfit to use.
82%
Total Score
90
100
89
80
The repository is owned by the goldnead user account rather than an organization, so there is no organizational maintenance-backup signal. This is partly offset by two active contributors and the repository's recent commit volume.
The repository has zero stars, forks, and watchers, providing no popularity-based reassurance. Because the package is only 36 days old and popularity is supporting rather than decisive evidence, this is a minor caution rather than a health verdict.
The repository uses Composer build tooling, but no security-scanning tools are configured. The missing security automation is a genuine transparency and maintenance gap, although the package still has build infrastructure.
The repository has no SECURITY.md or other declared security policy. This weakens vulnerability-reporting transparency and response expectations, especially for a package handling signed downloads and audit data.
One workflow, release-dist.yml, has top-level write permissions, while the other is read-only. Broad write permission increases CI supply-chain exposure and should be narrowed to the minimum required permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
laravel/framework Version ^12.40|^13.0 | — | — |
goldnead/statamic-entitlements Version ^1.0 | — | — |
pixelfear/composer-dist-plugin Version ^0.1 | — | — |
goldnead/statamic-brand-context Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.