Package Health

statamic/statamic

This is a mature, actively maintained Statamic project release with a history dating to 2020, 75 releases, 23 releases in the last 12 months, a stable non-prerelease version, and a repository that is neither archived nor inactive. Recent repository activity includes 11 commits from five maintainers over three months, ongoing pull-request activity, and organization backing, which substantially reduces abandonment and bus-factor concerns. The package has strong project scaffolding, tests, a README, a build tool, and a repository that clearly matches and documents the package. The main health concerns are the absence of any detected license declaration or license file, no security policy or security scanning tooling, and several lifecycle scripts that increase install/update complexity; these are meaningful transparency and operational-hygiene gaps but do not outweigh the strong maintenance evidence.

Latest v6.5.1PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Licensecaution

No declared license and no license file were detected in the artifact or repository, leaving the legal terms of dependency use unclear.

Lifecycle scriptscaution

Five Composer lifecycle scripts run during installation or updates, increasing install-time behavior and review surface; these are consistent with a project scaffold but still warrant scrutiny when depending on the package.

Repo toolingcaution

Composer is used as a build tool, but no security-scanning tools were detected; the build setup is present while security automation coverage is limited.

Security policycaution

No repository security policy was detected, reducing transparency about vulnerability reporting and coordinated response procedures.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
statamic/cms
Version ^6.0
laravel/tinker
Version ^3.0
laravel/framework
Version ^13.17

Weekly Downloads

Info

Last Published
13 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform