The repository is small and has no tests, changelog, or security policy, which limits transparency. Frequent releases and two equally active contributors provide useful maintenance evidence.
73%
Total Score
100
75
50
The release declares a proprietary license, so it is licensed rather than unlicensed; however, its proprietary terms may require developers to verify usage rights before adoption.
The package has no README, tests, changelog, or release notes. Missing tests and changelog are normal for a published artifact, but the absent README reduces consumer-facing transparency for an integration-focused addon.
Composer is used for builds, but no security scanning tool is reported. For a small addon this is a modest transparency gap, not evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a maintenance and transparency gap, but not a severe dependency risk on its own.
The single workflow is fully analyzed and has no reported dangerous sinks or audit findings, but its only action reference is unpinned, so the workflow does not fully protect against action-reference drift.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.