Usable with caveats: the package is clearly identified, licensed, documented, and actively published, but it is only 40 days old and all recent work comes from one maintainer. Treat it as a small, early-stage dependency rather than a mature project.
68%
Total Score
50
100
88
88
The registry namespace and repository are owned by the same individual, confirming consistent ownership but providing no organizational backing beyond that single maintainer.
The package is only 40 days old and has two releases, both published within a short period, so there is little history demonstrating long-term maintenance.
One contributor made all three commits in the last three months, leaving maintenance dependent on a single individual with no demonstrated handoff capacity.
The repository recorded three commits in the last three months, showing some activity, but the small amount of work provides limited evidence of sustained maintenance.
Composer is used as a build tool, but no security scanning tools were detected. For this very small package this is a hygiene gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/boost Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.