The single-maintainer project has no security policy, and both workflow actions are unpinned. A clear MIT license, repository tests, release notes, and a substantial readme provide useful transparency.
62%
Total Score
50
100
81
50
The package runs a post-autoload-dump Composer lifecycle script. This is a modest install-time trust consideration, although the signal does not show a broader or unusually risky script set.
Only one registry account has publish access. Because the repository is user-owned and the project is very new, this indicates limited publishing redundancy rather than established maintainer capacity.
The package is less than a day old and has only two releases, published about 82 minutes apart. This is too little history to establish durable maintenance, though the rapid second release shows active initial development.
There were no recorded commits or active maintainers in the last three months. Since the repository was created less than a day ago, this primarily means maintenance history is unproven rather than that activity has collapsed.
The repository uses Composer but reports no security scanning tools. Build tooling is present, while the absence of scanning is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/flux Version ^2.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
juaniquillo/laravel-backend-component Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.