This release appears suitable for dependency use: it is a stable non-prerelease version, was published recently, is not deprecated, and the linked organization-owned repository is active, correctly identified, and not archived. The package is licensed under MIT, has a focused dependency profile, and does not run install-time lifecycle scripts. The main concerns are a single active contributor, no repository security policy or security-scanning tooling, and no tests or changelog in either the artifact or repository; these reduce transparency and resilience but do not outweigh the strong evidence of recent maintenance and coherent packaging.
78%
Total Score
90
100
83
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.