The source includes tests, release notes, MIT licensing, and a repository that clearly matches the package. CI has weak controls, including unpinned actions and a high-confidence bot-condition warning.
22%
Total Score
50
69
50
Packagist marks the entire package as abandoned, with no replacement supplied. Package-level deprecation is a severe adoption and maintenance risk.
There has been only one release, published about 18 months ago, with no releases in the past 12 months. That provides little evidence of an actively maintained release line.
The repository recorded zero commits and zero active maintainers in the past three months. This weakens confidence that issues or compatibility problems will be addressed promptly.
The repository has no security policy. This is a transparency gap for a package handling application exports, although the README provides a security contact.
Version 0.1.0 is not a stable major release, indicating an immature API. This reinforces the risk created by the package being abandoned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^3.4 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.