The package is small and lightly documented, with no tests or security scanning to support future maintenance. Its matching repository is active enough to publish the current stable release, and the simple dependency set limits complexity.
68%
Total Score
50
100
88
83
One registry publishing account creates a thin publishing base, although the matching repository and project ownership show this is a single-maintainer project rather than an unexplained registry mismatch.
A README is present and the repository uses GitHub Releases, but the package and repository contain no tests; the missing changelog is normal packaging practice and not a gap by itself.
The registry namespace and repository are owned by the same individual account, providing direct ownership evidence but no organizational backing to mitigate the single-maintainer risk.
The repository has no commits and no active maintainers in the last 3 months. The recent release partly offsets this because it was published at the start of that period, but ongoing maintenance capacity remains uncertain.
There are no open issues or pull requests, and no issue or pull-request activity in the last month; this is neutral for a small package but provides little evidence of an active user community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^8|^9|^10|^11|^12|^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.