Its single runtime dependency and lack of install-time scripts keep integration relatively simple. Documentation and package-to-repository identity are unclear, while the project has no maintenance track record yet.
60%
Total Score
50
100
75
83
The published artifact has no README, tests, or changelog. Missing tests and changelog are normal for a published artifact, but a README is useful for a Statamic addon that consumers must configure.
The repository is owned by a user account rather than an organization, so there is no visible organizational backing to compensate for the thin project history.
This is the first release, published today, so there is no track record for maintenance or compatibility yet. Its age makes the absence of history understandable, but it still limits confidence.
There were no commits or active maintainers in the preceding three months. Because the repository is newly created today, this is mainly a lack of historical evidence rather than proof of abandonment.
The repository name does not match the package name, and the README could not be shown to mention the package. The mismatch may be legitimate, but package ownership is not clearly established by this signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.