Clear documentation, tests, changelog, and a matching repository make the package easy to evaluate. Maintenance is still lightly proven, with one recent commit from one contributor and no security policy or scanning; workflow references are also unpinned.
72%
Total Score
50
100
94
75
Only one registry account has publishing access. This is a modest publishing bus factor for a user-owned project and leaves little evidence of release handoff capacity.
The repository is owned by a user account rather than an organization, so the concentrated contributor and maintainer activity is not visibly backed by an organization that could hand off maintenance.
All recent commit activity comes from one contributor, giving the project a single-person bus factor. The matching repository and active release history help, but do not replace broader maintenance capacity.
Only one commit was recorded in the last three months, from one active maintainer. That is limited recent maintenance evidence for a package intended for application integration.
Composer build tooling is present, but no security-scanning tool is configured, leaving automated security coverage unconfirmed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.