The small repository clearly matches the package, with an MIT license, useful README, and release notes for this version. Maintenance has stopped for over two years, while the workflow uses four unpinned actions and two archived actions; no security policy is provided.
56%
Total Score
50
100
86
75
There were zero commits and zero active maintainers in the three months before collection. Combined with the old latest release, this indicates maintenance has effectively stalled.
The package has seven releases since June 2023, but its latest release was in May 2024 and it had no releases in the following 12 months. This is a meaningful maintenance concern for a Statamic integration.
Two issues remain open, with no new or closed issues and no pull-request activity in the last month. This adds evidence of limited ongoing support, though the small project size keeps it from being severe on its own.
The repository uses Composer build tooling, but no security scanning tools were detected. For a package that handles an analytics API token, the missing automated security checks are a modest transparency gap.
No security policy is present in the repository. This weakens the project's disclosure and response transparency, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.5 | — | — |
pixelfear/composer-dist-plugin Version ^0.1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.