Frequent releases show active publishing, while organization ownership and repository tests provide some support. Install-time scripts and the lack of security scanning add operational risk beyond the maintenance concerns.
44%
Total Score
50
83
50
The repository recorded zero commits and zero active maintainers in the last three months, despite the recent release, leaving current maintenance activity uncertain and raising abandonment risk.
Five install- and update-time Composer lifecycle scripts run package code automatically, increasing installation complexity and the amount of behavior a consumer must trust.
The linked repository is named fusebox rather than fuse and does not mention the package in its README, so ownership of this package by that repository is not clearly established.
The repository has no security policy, making vulnerability reporting and responsible disclosure less transparent.
The package is not on a stable major version, so its API and behavior may change more readily even though the current release is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/flux Version ^2.9.0 | — | — |
laravel/tinker Version ^2.10.1 | — | — |
stancl/tenancy Version ^3.9 | — | — |
laravel/fortify Version ^1.30 | — | — |
deployer/deployer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.