Its MIT licensing and matching organization repository make provenance clear. The short documentation and lack of repository security scanning add modest transparency concerns.
38%
Total Score
50
63
75
The package has made only two releases, both in January 2019, with no release in more than seven years. This is strong evidence of abandonment risk for a maintained dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of ongoing maintenance.
The repository has zero stars and forks and only two watchers. Popularity is supporting evidence rather than decisive, but these figures provide little community support to offset the inactivity.
The repository has no security policy. For a small package this is a modest transparency gap, though it is less serious than the absence of recent maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^1.1 | — | — |
laravel/framework Version >=5.0.0 | — | — |
dereuromark/media-embed Version ^0.4.4 | — | — |
timothyasp/nova-color-field Version ^1.0 | — | — |
dewsign/nova-repeater-blocks Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.