The repository has had no commits from any active maintainer in the last three months, and all six workflow actions are unpinned. Tests, release notes, a security policy, and a matching repository provide useful transparency.
68%
Total Score
63
100
94
100
Only one registry publishing account is listed, which is a modest publishing-resilience concern for a user-owned project, although repository activity and backing indicators provide some context.
The repository recorded zero commits and zero active maintainers in the last three months. For a package released only months ago, that inactivity is a meaningful maintenance concern.
There is one open issue and no issue or pull-request activity in the last month. This is limited evidence of community support, but not by itself evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected. The repository's security policy and documented security fixes partly compensate for this gap.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, leaving avoidable dependency-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^3.0 || ^4.0 | — | — |
illuminate/support Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/database Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.