It has a clear MIT license, a substantial README, repository tests, and no install-time scripts. The organization-backed repository is correctly linked, but its very short history leaves maintenance maturity unproven.
67%
Total Score
75
79
75
The package has five releases in roughly three hours and is effectively brand new, so the rapid initial cadence does not yet demonstrate sustained maintenance.
There were no commits or active maintainers in the prior three months, although the repository was updated very recently and the package is newly published; sustained maintenance is therefore unproven rather than clearly abandoned.
Composer build tooling is present, but no security scanning tool was detected, leaving a repository hygiene gap for a package handling service and portal functionality.
The repository has no security policy, reducing transparency for reporting vulnerabilities in a package with web-facing service components.
Version v0.2.3 is not a stable major release, so compatibility and API changes remain more likely while the project is still developing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
focalcrm/core Version self.version | — | — |
laravel/framework Version ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.