The package is clearly licensed and includes a substantial, domain-specific codebase with repository tests. Recent releases are frequent, but maintenance is concentrated in one contributor and the repository lacks a security policy.
68%
Total Score
50
50
94
67
The package declares 12 runtime dependencies, including framework, UI, permissions, export, and internal package components. This is a meaningful dependency surface that adds maintenance exposure but is consistent with the package's Laravel application scope.
The package runs a post-autoload-dump install-time script. This is a modest supply-chain and installation transparency concern, although no additional dangerous behavior is shown here.
Only one registry account, hwkdo, has publish access. The matching repository ownership and frequent releases provide some compensation, but publishing remains dependent on a single account.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This supports package identity while offering limited organizational maintenance redundancy.
One contributor made all commits in the last 3 months, giving the project a complete short-term contributor concentration and increasing continuity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^1.6.7 | — | — |
hwkdo/bue-laravel Version dev-main || ^0 | — | — |
maatwebsite/excel Version ^3.1 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.