Clear tests, release notes, and a matching repository make the package easy to inspect. Its workflow uses unpinned actions, while the project has no security policy yet.
68%
Total Score
75
100
83
67
The package has five releases, but they all arrived within about one day, leaving no meaningful long-term maintenance record yet.
There were no commits or active maintainers in the last three months, so the package has not demonstrated an established maintenance history; its very recent creation limits how strongly this weighs against it.
The repository has no stars, forks, or watchers. This is not decisive for a new package, but it provides no independent adoption evidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency gap.
The repository has no published security policy, so vulnerability-reporting expectations are unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.