The package is small and clearly documented, with repository tests and release notes for this version. Its release history is stale and recent repository activity has stopped; the workflow also leaves both actions unpinned and no security policy is published.
58%
Total Score
50
93
50
The package declares a post-autoload-dump install-time script. Lifecycle execution expands installation complexity and warrants inspection, but the signal provides no evidence that this script is harmful.
The latest registry release was over four years ago, with no releases in the last 12 months and only four releases overall. This weakens confidence that compatibility issues will be addressed promptly.
The repository recorded no commits and no active maintainers in the last three months. The repository was pushed more recently than the release, but current maintenance still appears inactive.
The linked repository has no published security policy. This is a transparency gap for a package that integrates into application templates, although it is not evidence of a security defect by itself.
The single workflow was fully analyzed and has no dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves avoidable build-integrity risk despite otherwise clean workflow behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^3.3 | — | — |
illuminate/view Version ^8.0 || ^9.0 | — | — |
illuminate/support Version ^8.0 || ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.