The package includes a substantial README, changelog, release notes, repository tests, and a matching source repository. Its single-user ownership, absent security policy, and lack of security scanning leave less evidence of long-term resilience.
67%
Total Score
50
79
67
The repository is owned by an individual account rather than an organization, so there is no organizational backing shown to compensate for a small maintainer base.
The package is only 0 days old with four releases clustered within about 1 day, so there is little evidence of an established release pattern yet.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, so users have no documented security-reporting process.
Version v0.2.1 is not on a stable major version, which signals an early-stage API and possible compatibility changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
laravel/sanctum Version ^4.0 | — | — |
laravel/framework Version ^12.40|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.