The package is licensed and has a clear source tree with repository tests and a changelog. Its README still contains template text, and installation runs a post-autoload-dump script, so inspect integration before pinning.
64%
Total Score
67
93
50
A post-autoload-dump install-time script runs during Composer installation. This is not inherently unsafe, but it adds execution behavior that consumers should understand before adoption.
The package includes a README and changelog, while the repository has tests. However, the README still contains untouched template text, reducing documentation transparency.
The repository owner is a user account rather than an organization, so there is no provided evidence of organizational handoff capacity to offset the concentrated contributor base.
All four recent commits came from one contributor, so maintenance depends entirely on a single active developer.
The repository has no security policy. That does not show a security defect, but it leaves vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^1.6.7 | — | — |
hwkdo/bue-laravel Version dev-main || ^0 | — | — |
livewire/livewire Version ^4.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.