Healthy and actively maintained, with strong release cadence, repository activity, documentation, and CI tooling. Review the concentrated contribution pattern and permissive workflow settings before adopting it in a sensitive application.
78%
Total Score
80
100
100
70
A post-autoload-dump install lifecycle script is present. This is a modest supply-chain and installation-complexity consideration, though no dangerous behavior is established by this signal alone.
One contributor made 58 of 63 recent commits, so maintenance is highly concentrated. The second active contributor and organization ownership partly compensate, making this a caution rather than a severe abandonment risk.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not a strong maintenance concern because the repository shows substantial recent commit activity, but it limits evidence of public support.
The repository has no published security policy, leaving vulnerability-reporting expectations and response procedures unclear.
Three workflows declare top-level write permissions and two omit top-level permissions entirely; although this is a repository-hardening gap rather than evidence of malicious behavior, it increases CI credential exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
centrex/tallui Version * | — | — |
livewire/livewire Version ^4.2 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
owen-it/laravel-auditing Version ^14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.