Clear documentation, MIT licensing, and a small dependency surface reduce adoption friction. Maintenance is concentrated in one contributor, and both workflow actions are unpinned, leaving modest continuity and build-reproducibility concerns.
84%
Total Score
83
100
100
75
One contributor made all 12 commits in the last 3 months, giving the project a 100% top-contributor share. The organization-owned repository provides some handoff capacity, but no second recently active contributor is shown.
No repository security policy was found. For a small addon this is a modest transparency gap, but it does not outweigh the active, tested release evidence.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, and it has no broad top-level write permission. However, both action references are unpinned, which leaves a build-reproducibility and action-change risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.