This is a young but currently healthy-looking package: it has four releases over 136 days, a recent release, an active non-archived organization-owned repository, tests, a changelog, a substantial README, and a complete MIT license. Maintenance activity is modest at two commits from two active contributors in the last three months, but the balanced contributor share and organizational backing reduce bus-factor concerns. The main reservations are the package's early 0.x maturity, very low repository popularity, and limited security-process transparency: no security policy or security scanning tooling was observed, and the workflow lacks top-level token permissions. It appears reasonable to depend on with normal version-pinning and review practices, but it is not yet as mature or security-transparent as an established package.
78%
Total Score
100
100
78
70
A post-autoload-dump install lifecycle script is present; this is a noteworthy execution surface, but the signal does not indicate a dangerous script or otherwise establish a severe dependency risk.
The package is only 136 days old with four releases, but releases occurred regularly, with a median interval of about 6 days and all four releases within the last 12 months. This supports active development while leaving long-term maturity unproven.
The repository has only 1 star, 0 forks, and 1 watcher, so there is little external adoption evidence. Popularity is supporting evidence rather than a requirement, and the active repository signals partly compensate.
Composer build tooling is present, but no security scanning tools were observed. The missing security automation lowers security-process transparency without proving the package is unsafe.
No repository security policy was found. This is a genuine transparency gap for reporting vulnerabilities, although it does not independently establish abandonment or maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/flux Version ^2.0 | — | — |
illuminate/view Version ^10.0|^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.