Clear documentation, a declared license, and no install-time scripts reduce adoption friction. The narrow dependency set helps, but there is little evidence of security process beyond the repository itself.
65%
Total Score
50
100
83
88
One registry maintainer is consistent with the single-person repository, but it provides little redundancy if that maintainer becomes unavailable.
The repository is owned by an individual account rather than an organization, so the concentrated maintainer and contributor base is not offset by visible organizational backing.
The package is only 97 days old with two releases and a median interval of about 43 days, so its long-term maintenance record is still limited.
One contributor made all two commits in the last three months, leaving maintenance highly dependent on a single person.
Only two commits were recorded in the last three months, indicating limited recent development activity even though the latest push is recent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.