Unpinned GitHub Actions references and no repository security policy leave modest process gaps. The MIT license, clear README, release notes, active two-person maintenance, and organization backing support adoption.
78%
Total Score
100
100
83
50
The package has 17 releases over about two years, but only one release in the last 12 months indicates a slower recent cadence; current repository activity partly compensates.
The repository has no stars or forks and only two watchers, limiting external validation; popularity is supporting evidence rather than a health verdict, and active commits compensate.
Composer is used for the build, but no security-scanning tool was detected, leaving a modest verification gap.
The repository has no security policy, reducing transparency about how vulnerability reports are handled.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned, and no top-level permissions block is present.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^4.0|^5.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.