The focused package has clear documentation, a matching source tree, and a recent release note. Its single-maintainer project lacks a security policy and has limited testing evidence.
61%
Total Score
50
100
88
88
Only one account has registry publish access. That is a narrow publishing base and increases continuity risk if the maintainer becomes unavailable.
The repository is owned by an individual account rather than an organization. Combined with one registry maintainer, this indicates limited visible project backing.
The package has only 2 releases over 455 days, with 1 release in the last 12 months and a median interval of about 284 days. This indicates slow maintenance, though the recent release shows the project is not abandoned.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That recent inactivity lowers confidence in ongoing maintenance, although the repository was recently pushed for the assessed release.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools are configured, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-html Version ^3.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.