Documentation and tests are present, and the package is clearly licensed with a matching repository. Its short history and stated temporary-fork status leave longer-term maintenance uncertain, while the repository has no security scanning or policy.
65%
Total Score
83
100
83
88
Only one release exists over roughly 110 days, so there is not yet evidence of an established maintenance cadence. The repository was pushed for this release, but that does not demonstrate sustained activity.
There are no open issues or pull requests and no recent issue or pull-request activity. With only one release, this provides little evidence of an established maintenance community.
The repository has zero stars, forks, and watchers. For a new package this is weak supporting evidence rather than a decisive health problem.
Composer is used for the build, but no security scanning tools were detected. That is a process gap for a package intended to be installed as a dependency.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^5.0 || ^6.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.