The project is only 29 days old, with five commits from one contributor and no security policy. It has repository tests, clear documentation, an MIT license, and organization backing, but the workflow uses two unpinned actions.
65%
Total Score
67
100
86
67
The package is only 29 days old and has three releases, all published within roughly one hour, so its longer-term maintenance record is unproven.
All five recent commits came from one contributor, leaving maintenance dependent on a single active developer.
The repository recorded five commits in the last three months, showing some activity, but the small volume limits evidence of sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving security-maintenance practices less transparent.
The repository has no security policy, so users lack documented guidance for reporting vulnerabilities in an integration that handles OAuth credentials and tokens.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
quickbooks/v3-php-sdk Version ^6.1 | — | — |
spatie/laravel-settings Version ^3.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.