Usable with caveats: the release is licensed, stable, clearly backed by its matching repository, and not deprecated or archived. However, it has had no releases or commits for about two years, with only one maintainer and no security policy, so long-term maintenance is uncertain.
58%
Total Score
33
100
81
75
The repository recorded no commits and no active maintainers during the last three months, and this inactivity has persisted for about two years since the last push.
Only one registry account has publish access, leaving limited publishing continuity if that maintainer becomes unavailable; the repository is user-owned rather than organization-backed.
The registry namespace and repository owner match, but both are tied to an individual account, so there is no organization-level backing to compensate for the thin maintainer base.
The package has eight releases, but the latest was about two years ago and there were no releases in the last 12 months, which weakens evidence of ongoing maintenance.
The repository uses Composer, but no security-scanning tools are reported, leaving a transparency and maintenance gap for a package with server-side dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^4.0 | — | — |
laravel/framework Version ^10.0|^11.0 | — | — |
laravel/vapor-core Version ^2.37 | — | — |
spatie/laravel-medialibrary Version ^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.