Its two runtime dependencies and lack of install-time scripts keep the integration surface straightforward. Documentation and security-process gaps, plus a fully unpinned workflow action, warrant checking the source before adoption.
64%
Total Score
67
100
67
75
The package has no README, leaving consumers without usage guidance, while the absence of tests and a changelog is normal for a published artifact and is not counted against it here. The missing consumer documentation is a minor transparency gap for an addon.
The repository is owned by an individual user rather than an organization, so the small contributor base has no visible organizational backing to compensate for limited maintenance capacity.
The package is only 99 days old, with 13 releases concentrated over eight days and a median interval of 0 days. This shows active initial iteration but provides limited evidence of long-term maintenance.
Two commits from two active maintainers were recorded over the last three months. The balanced contributor activity is positive, but the very low volume limits evidence of sustained maintenance.
The repository has zero stars, forks, and watchers. This provides no external adoption signal, though popularity alone is only supporting evidence and does not establish that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.