This release appears suitable to depend on, with strong repository and package hygiene: it is a stable, non-deprecated release backed by an active, non-archived repository, tests, changelog, documentation, security policy, CI tooling, and clean workflow-risk checks. The main reservations are that the project is young at 72 days, all 11 recent commits came from one contributor, one CI workflow lacks top-level permissions, and the package uses post-install and post-update scripts. Organization ownership and recent merged pull requests provide some mitigation, but the limited operating history and concentrated maintenance base warrant continued monitoring before relying on it for highly critical functionality.
78%
Total Score
80
100
89
80
The package defines post-install and post-update Composer scripts, which increase installation-time execution exposure and deserve review, although their presence alone does not establish unsafe behavior.
The package has five releases over 72 days with a median interval of about 15 days, indicating active early development but limited historical maturity.
All 11 recent commits came from one contributor, creating a clear bus-factor risk; organization ownership partially mitigates handoff concerns but does not demonstrate a second active maintainer.
The repository recorded 11 commits in the last three months, showing recent activity, but only one maintainer was active during that period, limiting evidence of sustained maintenance capacity.
The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity is not decisive and the package has stronger activity and hygiene signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jooservices/dto Version ^3.2 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
jooservices/exceptions Version ^4.0 | — | — |
mongodb/laravel-mongodb Version ^5.10 | — | — |
jooservices/laravel-repository Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.