This is a generally healthy, established release: the package has existed for over five years, has 46 releases including 7 in the last 12 months, releases about every 21 days, is on a stable non-prerelease major version, is not deprecated, and was pushed very recently. The main adoption risk is maintenance concentration: all five commits in the last three months came from one contributor, with no second active contributor, while the repository also lacks tests and a security policy. The linked repository does reference the package in its README, and the artifact contains a license file, buildable source tree, and no install-time lifecycle scripts, which provide useful transparency and reduce operational risk.
78%
Total Score
70
100
88
90
A substantive README is present and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. The missing tests are a meaningful quality and maintenance gap for a feature-rich application addon, while the missing changelog is less serious because releases are available.
The repository is owned by a user account rather than an organization, so there is no organization-level maintenance handoff evidence to offset the concentrated contributor activity. The package does nonetheless have a long release history and recent repository activity.
All five recent commits came from one contributor, giving a 100% top-contributor share and a one-person recent contributor base. With a user-owned repository and no second active contributor shown, this creates a meaningful continuity risk.
There were five commits in the last three months, demonstrating recent maintenance, but only one active maintainer produced them. The activity is therefore positive but somewhat fragile.
Composer build tooling is present, supporting reproducible project construction, but no security-scanning tools are reported. The missing scanning is a hygiene gap rather than a severe health finding because no maliciousness judgment is being made here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
whitecube/lingua Version ^1.0 | — | — |
spatie/schema-org Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.