Usable with caveats: the package has a strong recent release history and is not deprecated, but the linked repository shows no commits in the last three months and lacks tests, a changelog, and a security policy. Validate changes carefully before adopting it as a core dependency.
68%
Total Score
50
100
88
88
The artifact and repository include a substantial README, but neither contains tests or a changelog. For a Laravel package with broad database, UI, and broadcasting functionality, the lack of visible tests reduces confidence in maintenance and upgrade safety.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization. This provides some ownership continuity while leaving a relatively narrow apparent backing structure.
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance concern, especially for a package with frequent registry releases, because the release cadence is not supported by observed recent source activity.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a transparency and maintenance gap, though it is not severe enough alone to make the package unfit.
No repository security policy was found. For a package handling application data, broadcasting, and database-related functionality, this leaves vulnerability reporting and maintenance expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jenssegers/agent Version * | — | — |
maatwebsite/excel Version * | — | — |
bangsamu/library-clay Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.