Consumer guidance is sparse, and the source project has not changed since May 2023. Its single release and package/repository name mismatch make long-term ownership harder to verify; pinning this version should be treated as a maintenance compromise.
42%
Total Score
64
75
The package has only one release, published in May 2023, with no releases in the last 12 months. This provides strong evidence of limited maintenance activity, although it is not deprecated.
The artifact has no README, while its lack of tests and changelog is normal packaging practice. For a reusable Livewire component library, missing consumer documentation is a meaningful transparency gap.
The repository name does not match the package name, and no README package mention was available. That makes it harder to verify that the linked repository is the intended source, beyond the ordinary naming differences of a subpackage.
The repository is not archived, which preserves the possibility of future maintenance, but it was last pushed in May 2023. This reinforces the long period without observed project activity.
The linked repository has no security policy. This is a modest transparency and maintenance gap, though the package has no reported lifecycle install scripts and no workflow audit findings.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.