The organization-backed repository matches the package, has a changelog and release notes, and is not archived. Documentation lacks a security policy, while workflow references are all unpinned and recent development activity is quiet.
68%
Total Score
75
83
75
The package has existed for about 3 years and 9 months with 9 releases, but only 1 release in the last 12 months and a median interval of about 147 days indicate a slow cadence.
The repository recorded no commits and no active maintainers in the last 3 months. The recent release partly compensates for this, but the quiet development window still raises maintenance concern.
The repository has 1 star, 0 forks, and 3 watchers, offering little independent evidence of broad adoption; this is supporting context rather than a verdict.
Composer build tooling is present, but no security scanning tool was detected, leaving the project's automated security coverage unclear.
No security policy was found in the repository, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
bolechen/nova-activitylog Version ^0.5.0 | — | — |
justbetter/laravel-magento-stock Version ^2.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.