Documentation and security process are minimal, and the workflow relies on an unpinned action. Recent commits from two contributors provide maintenance evidence, but the project remains young with little visible adoption.
64%
Total Score
75
100
75
50
The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for a small compiled-style package, but the absent README makes integrating this addon less transparent.
The package is only 79 days old, with all 11 releases arriving within that period and a bursty release interval. This shows active initial development but not yet a mature long-term maintenance record.
Two contributors were active in the last 3 months, but the leading contributor made about 69% of commits. The second active contributor partly offsets the concentration, leaving a modest maintenance risk.
The repository has zero stars, forks, and watchers. Because the package is very young, this is weak supporting evidence rather than proof of poor quality, but it provides little external validation.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.