The package is clearly licensed and documented, with a clean artifact and no install-time scripts. Workflow permissions and unpinned actions add hygiene concerns, while the repository has no security policy.
67%
Total Score
75
100
83
75
The repository is owned by an individual user rather than an organization, so the single-contributor concentration has no visible organizational backing to offset it.
This is a 54-day-old package with only one release, so there is little evidence of sustained release maintenance yet.
One contributor made all eight commits in the last three months, leaving maintenance concentrated with a single person.
The repository has no stars, forks, or watchers; this is weak supporting evidence, but popularity alone does not determine health for a young package.
No security policy is present in the repository, reducing transparency about how users should report vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.