The small contributor base and missing security policy leave limited evidence for long-term support. Recent releases and ongoing commits are reassuring.
70%
Total Score
75
70
75
The manifest declares a proprietary license and no license file was found. This provides a licensing declaration but may restrict use or redistribution in projects expecting open-source terms.
The package is young at 82 days, with four releases and a median interval of about 8 days. That shows active early development but provides little long-term maintenance history.
Three contributors are active, but one accounts for 5 of 7 commits. That concentration leaves maintenance somewhat dependent on one person.
Composer is used for the build, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap.
The repository has no security policy. For a small addon this is not severe, but it gives users no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.