The README, release notes, repository tests, and MIT licensing provide useful transparency. Workflow references are unpinned, so build reproducibility is weaker.
67%
Total Score
75
100
88
50
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance warning, although the recent release and recent push show the project has not clearly been abandoned.
The repository uses Composer for its build, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
No security policy is present in the repository. That reduces transparency for reporting and handling vulnerabilities, but does not by itself show that maintenance has stopped.
The assessed version is v3.0.0-alpha.1, so consumers should expect possible API changes and incomplete stabilization. The low recent prerelease share provides some compensating evidence, but this specific release remains explicitly pre-release.
The only workflow was fully analyzed with no reported audit findings and no untrusted checkout or injection sinks. However, all 3 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0|^13.0|dev-master | — | — |
livewire/livewire Version ^3.0|^4.0|dev-main | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.