Documentation, release notes, and a matching source repository improve transparency. Its single runtime dependency and lack of install-time scripts keep the package straightforward to integrate, but these positives do not offset the adoption risk.
15%
Total Score
33
100
50
83
Packagist marks the entire package as abandoned, with no replacement specified. Package-level deprecation is a severe adoption risk even though the release itself is stable.
The latest release was May 2024, with no releases in the following 12 months and nine releases overall. This indicates a prolonged release gap for a package that has since been abandoned.
There were zero commits and zero active maintainers in the three months measured. This provides no evidence of ongoing maintenance capacity.
The linked repository is archived, indicating the project is no longer intended for active maintenance. Its last push was in September 2025, which does not offset the archived status.
The package is owned by the individual user jacksleight rather than an organization. This does not itself indicate a problem, but it provides less visible organizational backing for continued maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.