This is a young but reasonably well-structured package with an MIT license, tests in both the artifact and repository, a matching source repository, minimal runtime dependencies, and recent activity from two contributors under an organization-owned project. Its main risks are limited maturity—only 3 days old with two releases at pre-1.0 version v0.1.2—and the absence of a security policy; popularity is also unestablished. The available evidence supports cautious adoption rather than treating the package as mature and broadly proven.
78%
Total Score
90
100
81
90
The package is only 3 days old and has two releases, so maintenance history and long-term stability are not yet demonstrated.
There were two commits in the last 3 months from two active maintainers, demonstrating recent activity but still offering only a small maintenance history.
Composer build tooling is present, but no security scanning tools were detected; the missing scanning is a transparency and assurance gap rather than evidence of a severe defect.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting expectations unclear.
Version v0.1.2 is not a stable major release, which signals an immature API and greater compatibility risk for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.