It has a clear MIT license, a substantial package tree, and repository tests plus a changelog. The project is still pre-1.0, and all recent commits come from one contributor. No security policy or scanning is provided, while release activity remains strong.
67%
Total Score
63
100
79
50
Only one registry maintainer account is listed. This is a modest publishing-bus concern, and the repository evidence also shows concentrated development.
The artifact includes a 3,016-character README and changelog, while the repository has tests and a changelog. The README still contains template text and lacks a finished package description, a minor transparency gap.
The registry namespace and repository owner match, but the owner is a user account rather than an organization. This provides no additional organizational handoff evidence.
One contributor made all 21 commits in the last three months, leaving no demonstrated handoff capacity and increasing abandonment risk if that person becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected. This weakens automated assurance without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^1.6.7 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
hwkdo/intranet-app-base Version dev-main || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.