The repository matches the package, and the README explains installation and use clearly. Its small scope and simple dependency profile help, but maintenance activity and security oversight are limited.
60%
Total Score
50
100
83
67
A post-update Composer script runs during dependency updates, adding some execution surface beyond ordinary package contents, though it is not an install-time script.
The registry namespace and repository are owned by the same individual account, which is consistent ownership but does not provide organization-level maintenance capacity.
Only three releases exist, with no release in the last 12 months and the latest published in March 2023; this indicates a mature-looking but stale release cadence.
There were no commits or active maintainers in the measured three-month period, which is a meaningful maintenance concern for a package whose last registry release was in 2023.
The repository has only 3 stars and 5 forks, indicating limited external adoption; this is supporting caution rather than evidence that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^4.0 | — | — |
laravel/framework Version ^8.0|^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.