This is a generally healthy and actively maintained release: it has 37 releases over roughly 2.9 years, 11 releases in the last 12 months, a stable non-prerelease major version, a non-deprecated registry status, a matching and README-referencing repository, and recent commits from two contributors. The main concerns are limited recent activity (only 2 commits in 3 months), no recent issue or pull-request closure activity, no repository security policy or security-scanning tooling, and no tests or changelog in the package or repository. These are meaningful transparency and maintenance gaps but do not outweigh the package's release cadence, active repository status, licensing, and evidence of a real maintained project.
82%
Total Score
60
100
89
90
Only one account has registry publish access, creating publishing continuity risk, although repository activity shows a second recent contributor and registry access is not evidence of actual maintenance capacity by itself.
A substantial README documents compatibility, installation, usage, and configuration, but neither the artifact nor repository contains tests or a changelog. The documentation compensates for part of the gap, while the lack of tests and release notes remains a modest hygiene concern.
The repository is owned by a user rather than an organization, so there is no organization-level maintenance backing to offset the small registry maintainer base.
Only 2 commits were recorded in the last 3 months, showing limited recent development activity. This is partly offset by the package's strong release cadence and the fact that two maintainers were active.
There are 29 open issues and 4 open pull requests, but no new or closed issues and no merged pull requests in the last month. The backlog and lack of recent resolution indicate a modest maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tinymce/tinymce Version ^8.0 | — | — |
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.92.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.