Usable with caveats: the package is actively released, clearly licensed, well documented, and backed by a matching organization repository. It is still young, with only two commits in three months from one contributor, and several workflows lack explicit token permissions.
74%
Total Score
67
100
93
67
The package is only 118 days old but has 15 releases, with the latest published today and a median interval of about 6 hours. This shows active iteration, though the short history leaves limited evidence of long-term stability.
One contributor made 100% of the two commits in the last three months. Because the repository is organization-owned, maintenance can potentially be handed off, but no second active contributor is shown.
Only two commits were recorded in the last three months, all from one active maintainer. The recent release activity partly offsets this, but the repository provides limited evidence of sustained engineering activity.
The repository has no SECURITY.md or other declared security policy. This is a transparency gap for a package that adds application-facing observability and playground functionality.
Three workflows omit top-level token permissions and one declares top-level write access. Although no dangerous workflow behavior was detected, the permissions configuration is less restrictive than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.10|^0.11 | — | — |
livewire/livewire Version ^4.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.