The repository has focused tests, a clear README, matching package sources, and a permissive license. Action references are all unpinned, and there is no security policy or automated security scanning, so operational hygiene is still limited.
62%
Total Score
88
100
81
75
One registry maintainer is consistent with a user-owned project, but it leaves little visible publishing redundancy for a package intended as a dependency.
Only two releases exist, both published within about 15 minutes, so there is not yet evidence of an established maintenance pattern.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest source-maintenance gap.
The repository has no security policy, which is a transparency gap for a package handling access-controlled media and audit records.
Version v0.1.1 is not a stable major release, indicating an early API and maintenance stage rather than a mature dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
statamic/cms Version ^6.0 | — | — |
laravel/framework Version ^12.40|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.