The package includes tests, release notes, and a security policy, with organization backing that supports continued maintenance. Confirm the repository mapping before adoption; its workflow actions are also unpinned.
73%
Total Score
100
93
83
The repository name does not match the package name and its README does not mention the package, so the registry-to-source relationship should be confirmed despite the repository appearing related to the Statamic addon.
All nine analyzed action references are unpinned, creating avoidable workflow supply-chain drift; the high-confidence template-injection finding is a workflow hygiene concern, while the low-confidence cache findings do not materially add risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
laravel/prompts Version ^0.3.12 | — | — |
shopify/shopify-api Version ^6.1.1 | — | — |
pixelfear/composer-dist-plugin Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.