The repository has no security policy, no security scanning, and uses a post-autoload-dump install script. Its MIT licensing, matching repository, and clear README provide useful transparency, but the project has little visible adoption.
52%
Total Score
33
100
83
50
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the single-release history, this is meaningful evidence of inactivity.
The package runs a post-autoload-dump install-time script. The signal gives no further detail about its behavior, so this is a modest transparency and installation-risk concern.
One registry maintainer is responsible for publishing the package. The repository is user-owned rather than organization-backed, so the narrow publishing base provides limited continuity.
The package and repository are both owned by the same individual account, and no organization backing is shown. This is consistent ownership but leaves a thin continuity base.
There has been only one release, published 508 days ago, with no releases in the last 12 months. This gives little evidence of an established maintenance cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mews/purifier Version ^3.4.3 | — | — |
laravel/framework Version >=10.0 <12.9.9 | — | — |
illuminate/support Version >=10.0 <12.9.9 | — | — |
spatie/laravel-html Version ^3.0 | — | — |
yajra/laravel-datatables Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.