Clear licensing, installation guidance, and a security policy support practical adoption. The organization-backed project is current and not archived, but recent work is concentrated in one contributor and the repository has no security-scanning tooling.
69%
Total Score
75
50
83
100
Ten runtime dependencies create a moderately broad dependency surface for a security-focused Laravel package, increasing maintenance exposure without making the release unfit by itself.
The package has existed for about 5 years 10 months with 31 releases, but only one release was published in the last 12 months; the latest release is recent, so this is a mild maintenance concern rather than abandonment.
All 3 recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second recently active contributor is shown, leaving a real concentration risk.
There are no open issues and one open pull request, but no issues or pull requests were closed in the last month; this offers limited evidence of responsive community maintenance.
The repository has only 2 stars and 2 forks, providing little community validation; popularity is supporting evidence, so this is only a modest caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
diviky/bright Version ^7.0 | — | — |
pragmarx/recovery Version ^0.2 | — | — |
bacon/bacon-qr-code Version ^2.0 | — | — |
bepsvpt/secure-headers Version ^9.0 | — | — |
matomo/device-detector Version ^3.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.