The package is very young, with only 40 days of release history and three commits, while two maintainers are active. Its proprietary license, absent security policy, and single unpinned workflow action reduce transparency, though the repository is active, non-archived, stable, and has no audited workflow findings.
68%
Total Score
75
100
70
67
The manifest declares a proprietary license, with no detected license text or license file in the package or repository. This limits transparency and may restrict adoption.
The package is only 40 days old with six releases, so its maintenance record is too short to establish long-term stability. The recent release activity is a modest positive but does not offset the limited history.
Two contributors are active, although the leading contributor made two of three recent commits. The concentration is a mild resilience concern rather than a severe single-maintainer risk.
The repository name does not exactly match the package name, and no README package mention was collected. This creates some uncertainty about package ownership, although the repository URL is explicitly named for the addon.
The repository has no security policy. For a small package this is a transparency gap, but it is not by itself evidence of unsafe maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.