Usable with caveats: it is actively developed, licensed, tested in the repository, and not deprecated or archived. Adoption carries single-contributor and workflow-permission risks, while the project is still only 41 days old.
72%
Total Score
90
100
89
60
One workflow uses pull_request_target for Dependabot auto-merge, which requires careful trust-boundary handling, but no untrusted checkout or script-injection pattern was detected.
A post-autoload-dump install script runs during Composer installation; this is common for Laravel packages but adds install-time behavior that should be reviewed.
The package has 12 releases in 41 days with a median interval of about 2 days, showing strong current activity but limited evidence of long-term stability.
All 108 commits in the last 3 months came from one contributor, creating a real continuity risk; organization backing provides some ability to hand maintenance off but does not remove the concentration.
The repository has 9 stars and no forks or watchers, indicating limited adoption evidence; popularity is only supporting evidence and does not outweigh the strong recent maintenance signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^1.0 | — | — |
livewire/livewire Version ^3.0||^4.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
mallardduck/blade-lucide-icons Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.