The included tests, release notes, and MIT licensing improve confidence. Its tiny pre-1.0 release history and no commits since May 2024 leave maintenance uncertain, while workflow references are unpinned.
58%
Total Score
75
100
81
75
Only two releases were published, with the latest on May 29, 2024 and none in the following 12 months. This is a meaningful maintenance concern for a young package.
There were no commits and no active maintainers in the measured three-month period. Combined with the old latest release, this raises abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, though not evidence of an unsafe release by itself.
The repository has no published security policy. This weakens vulnerability-reporting transparency for an integration package, but does not by itself make the release unfit.
Version 0.0.2 is not a stable major release, so its API and behavior may still change. The package is not marked as a prerelease, which offers limited compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
escolalms/auth Version ^0 | — | — |
escolalms/cart Version ^0 | — | — |
escolalms/core Version ^1 | — | — |
laravel/framework Version >=8.0 | — | — |
escolalms/settings Version ^0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.