The project has clear upgrade notes, tests, frequent releases, and active recent work. Its small contributor base and fully unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
76%
Total Score
75
50
100
63
The application declares 30 runtime dependencies, including substantial framework, database-adjacent, document, AI, and monitoring components. This breadth increases update and compatibility surface, but fits the package's full web-application scope.
The package uses four Composer lifecycle scripts, including post-update and post-create hooks. These are relevant installation complexity, though they are common for a Laravel application and are not by themselves evidence of poor health.
The repository is owned by a personal account rather than an organization, so the heavily concentrated recent commit activity has no demonstrated organizational handoff buffer.
Two contributors were active, but one made 77 of 78 recent commits, leaving maintenance highly concentrated and making continuity dependent on one person.
The repository has no published security policy, reducing transparency about vulnerability reporting and response for a self-hosted financial application.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-70844 kantorge/yaffa is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.0.0. | 0.0.0 - 2.0.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.14 | — | — |
laravel/ui Version ^4.6 | — | — |
league/csv Version ^9.21 | — | — |
brick/money Version ^0.11.2 | — | — |
bkwld/cloner Version ^3.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.