Usable with caveats: the release is clearly licensed, documented, tested in its repository, and backed by a matching non-archived project. It is still a young package with no commits in the last three months, no security policy, and some workflows using broad write permissions.
62%
Total Score
50
100
83
70
A post-autoload-dump install-time script is present. This is an additional installation behavior that merits review, but the signal does not show a dangerous action by itself.
The registry namespace and repository owner match, but the owner is an individual rather than an organization. This is consistent ownership, though it offers less visible continuity than established organizational backing.
The package is young, with two releases over about seven months and a median interval of about 39 days. This gives some release evidence but limited history for judging long-term maintenance.
The repository had zero commits and zero active maintainers in the last three months. For a package this young, that is a meaningful maintenance concern even though the latest release was recent relative to its history.
The repository has no stars, forks, or watchers. Popularity is only supporting evidence, but the absence of any adoption signal adds uncertainty for a young package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^3.0||^4.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.