Usable with caveats: it has a matching organization-backed repository, a stable release, clear licensing, and recent release activity. However, the repository shows no commits or active maintainers in the last three months, has little community activity, and lacks security scanning and a security policy.
68%
Total Score
50
100
89
90
The repository recorded zero commits and zero active maintainers during the last three months. Although a release was published and the repository was pushed on May 5, 2026, the recent absence of development activity raises maintenance and abandonment concerns.
There are two open issues and one open pull request, with one new issue in the last month but no closures or merged pull requests. This indicates some user activity without evidence of responsive resolution.
The repository has only 3 stars, 3 forks, and 1 watcher. This is limited supporting evidence and lowers confidence in broad community validation, but popularity alone is not a decisive health problem for a small addon.
Composer is used as a build tool, but no security scanning tools are configured. The missing scanning reduces automated assurance, though it is a hygiene gap rather than proof of an unsafe release.
The repository has no security policy. For an addon that exposes frontend administrative functionality, the absence of documented vulnerability-reporting guidance is a meaningful transparency gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.