Healthy and actively usable, with clear documentation, tests, licensing, and a steady release history. Recent repository work is limited to one commit from one contributor, so future maintenance depends heavily on a single person.
78%
Total Score
63
100
94
88
The repository is owned by an individual user, so the single-person maintenance base is not compensated by organization-level backing.
One contributor made all commits during the last 3 months, concentrating maintenance responsibility in a single person. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset that concentration.
Only one commit was recorded in the last 3 months, which is a limited level of direct development activity despite the recent release and repository push.
Composer build tooling is present, but no security scanning tools were detected. The separate security policy and clean workflow findings provide some compensation, so this is not a severe concern.
All three workflows lack top-level token permissions declarations. Although none requests explicit write access, explicitly restricting workflow permissions would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lakm/nopass Version ^1.0.5 | — | — |
mews/purifier Version ^3.4 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
spatie/laravel-honeypot Version ^4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.