Usable with caveats: it is actively published, stable, and backed by a matching repository, but maintenance depth and transparency are limited. No tests, no license, no security policy, and zero commits in the last three months increase the risk of relying on it long term.
58%
Total Score
50
100
78
90
No license declaration or license file was found in the package or repository, leaving reuse and redistribution terms unclear.
Only one registry account has publish access, which creates a limited publishing base. The matching user-owned repository provides direct ownership continuity, but does not remove the single-maintainer continuity risk.
The package includes a README and the repository uses GitHub Releases, but neither the artifact nor repository contains tests or a changelog. For a code-generation package, the missing tests reduce confidence that generated output remains reliable.
The registry namespace and repository owner match, and the owner is an individual rather than an organization. This supports package identity but offers less organizational continuity than a backed project.
The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance concern even though the repository was recently pushed and the registry has released four versions in the last year.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10|^11|^12|^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.