The repository includes tests, a matching README, and organizational backing. Its MIT license and lack of install scripts reduce adoption friction, but ongoing maintenance is not yet demonstrated.
62%
Total Score
75
79
75
The package is effectively new: it is 0 days old with five releases clustered within hours. This shows active initial publishing but provides no meaningful long-term maintenance history.
The repository records zero commits and zero active maintainers over the last three months. Because the package is newly published, this is partly explained by its age, but it still leaves maintenance capacity unproven.
Composer is used for the build, but no security-scanning tool is reported. For a newly published package this is a modest transparency and assurance gap.
The repository has no security policy. This does not show a security defect, but it leaves vulnerability-reporting and response expectations undocumented.
The release is v0.2.3 rather than a stable major version, so compatibility and API maturity are not yet established.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
focalcrm/core Version self.version | — | — |
laravel/framework Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.