The package is licensed and backed by repository tests, a changelog, and sustained recent work. Its install-time script and single-contributor maintenance model warrant extra caution for long-term use.
68%
Total Score
67
94
67
The package runs a post-autoload-dump lifecycle script during installation. This is a meaningful install-time surface and deserves caution even though the signal does not show that the script is harmful.
The repository is owned by a user account rather than an organization, so there is no provided organizational backing to offset the concentrated contributor activity. The matching registry and repository owner still support package identity.
One contributor made all 33 commits in the last three months, leaving no demonstrated handoff capacity. This creates a real continuity risk for a package with frequent ongoing changes.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a package that manages intranet asset workflows and database records, the lack of a documented reporting process reduces transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^1.6.7 | — | — |
maatwebsite/excel Version ^3.1 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.