The README, release notes, and matching repository make the package straightforward to evaluate. Its workflows use unpinned actions and the repository has no security policy or scanning tools, adding maintenance and build-integrity concerns.
58%
Total Score
50
100
81
50
The latest release was nearly three years ago, with no releases in the last 12 months, despite a reasonably regular earlier cadence. This is a substantial maintenance concern, though the package is not marked deprecated.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap. The repository remains available and was updated alongside the latest release, but current maintenance capacity is unclear.
The repository uses Composer for builds, but no security scanning tools were detected. This weakens ongoing supply-chain and dependency oversight without showing an immediate failure.
No security policy was found in the linked repository, reducing transparency around vulnerability reporting and maintenance expectations. This is a process gap rather than evidence of an unsafe release.
Version v0.2.4 is not a stable major release, which suggests a less mature compatibility commitment. It is not labeled a prerelease, providing some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^2.12|^3.0|^4.0 | — | — |
hammerstone/refine-laravel Version ^0.3.4|^0.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.