The README clearly explains installation, requirements, and the upgrade path, while the package has only one runtime dependency. The linked repository matches the package, is not archived, and has no risky workflow configuration.
62%
Total Score
75
100
88
88
The package is brand new, with 10 releases all published within the same day and a median interval of 0 days. This shows active initial publishing but provides no long-term maintenance track record.
There were 0 commits and 0 active maintainers in the last 3 months. Because the package is newly published, this is primarily limited evidence of maintenance capacity rather than proof of abandonment, but it still lowers confidence.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap for a small package.
The repository has no security policy. This is a transparency gap, though the package is small and the absence does not by itself indicate that it is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.