Recent releases, tests, release notes, and a readme support ongoing maintenance. Organization backing and read-only, fully pinned workflow permissions further improve confidence.
84%
Total Score
88
100
100
67
The package runs a post-autoload-dump lifecycle script during installation. This is an additional install-time execution surface and merits some caution even though no dangerous behavior is shown here.
All 21 commits in the last 3 months came from one contributor, giving the project a single-person operational dependency. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has no SECURITY.md policy. This is a transparency and vulnerability-reporting gap, but it is not severe enough to outweigh the package's active release and commit history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.0 || ^6.0 | — | — |
laravel/framework Version ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/support Version ^11.0 || ^12.0 || ^13.0 | — | — |
marcorieser/statamic-livewire Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.