Package Health

rapidez/statamic-query-builder

Regular releases, recent commits, four contributors, and clear licensing provide a solid maintenance base. The repository is active and backed by an organization, but its workflows use 11 unpinned actions and lack a security policy. Pin this version while workflow hygiene is improved.

Latest 3.2.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, although active development partly reduces abandonment concern.

Workflow auditcaution

All 11 analyzed action references are unpinned, so workflow dependencies can change unexpectedly; one workflow also grants top-level write permissions. The audit found no untrusted checkout, script injection, or high-severity findings, limiting this to a hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kevin Meijer
Bob Wezelman

Direct Dependencies

DependencyLast ReleaseScore
rapidez/core
Version ^5.0
—
—
statamic/cms
Version ^6.0
—
—
rapidez/statamic
Version ^8.0
—
—
elasticsearch/elasticsearch
Version ^8.19
—
—
rapidez/laravel-scout-elasticsearch
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform