This release appears actively maintained and reasonably transparent: it is not deprecated or archived, has a substantial README and source tree, includes repository tests, uses Composer and security scanning, and shows 260 commits in the last three months. The main concerns are that the project is only 83 days old, remains pre-1.0, all recent commits come from one maintainer, the repository has no popularity or issue activity, and no security policy or changelog is provided. It is a plausible dependency, but its young age and single-maintainer concentration warrant monitoring and a review of release changes before adoption.
72%
Total Score
60
50
83
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jenssegers/agent Version ^2.6 | — | — |
andydefer/laravel-otp Version ^1.2.14 | — | — |
andydefer/directive-forge Version ^2.17.50 | — | — |
andydefer/laravel-nemesis Version ^1.16.16 | — | — |
andydefer/laravel-notification Version ^1.9.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.