The repository is small and has no security policy or automated security scanning, while the release remains an alpha. MIT licensing, a usable README, tests in the repository, and organization backing provide useful transparency.
38%
Total Score
63
67
50
Only two releases were published, with the latest in November 2019 and none in nearly seven years. That long silence is strong evidence of abandonment risk.
The repository had no commits and no active maintainers in the past three months; its last push was more than three years ago. This materially lowers confidence in ongoing maintenance.
There were no new or closed issues or pull requests in the past month, despite one open issue and two open pull requests. This supports the broader picture of stalled maintenance.
Composer is used for the build, but no security-scanning tool is configured. The missing scanning is a modest supply-chain hygiene gap.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and response-readiness gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atk4/ui Version ^1.7 | — | — |
laravel/framework Version 5.8.* | — | — |
spatie/laravel-permission Version ^3.2 | — | — |
joedixon/laravel-translation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.