The MIT license, README, tests, and recent GitHub release provide useful project context. Its large runtime dependency set and install-time scripts increase operational complexity, while the lack of a security policy leaves fewer documented safeguards.
68%
Total Score
67
50
88
50
The package declares 38 runtime dependencies, including Laravel, Filament, cloud SDKs, database integrations, and payment or messaging-related components. That breadth increases compatibility and maintenance surface area for adopters.
Four install or update lifecycle scripts run automatically, including post-create and post-update commands. This is common for Laravel applications but adds installation behavior that consumers must understand and control.
The repository is owned by an individual user rather than an organization, so the highly concentrated contributor activity has no visible organizational backing to offset its continuity risk.
The package is about 15 months old with five releases and two releases in the last 12 months, with a median interval of about 61 days. This shows ongoing publication but not a highly mature release history.
Although three contributors were active, one contributor made 348 of 363 recent commits, or about 96%. That concentration creates a meaningful continuity risk if the primary maintainer becomes unavailable.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nelexa/zip Version ^4.0 | — | — |
mews/captcha Version ^3.4 | — | — |
laravel/octane Version ^2.15 | — | — |
laravel/tinker Version ^2.11 | — | — |
tuupola/base58 Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.