Usable with caveats: the package is actively released, clearly tied to an organization-owned monorepo, and has source tests in its file tree. It is only 36 days old, activity is concentrated in one contributor, and the repository lacks a security policy.
68%
Total Score
67
100
81
90
The package is only 36 days old but has 51 releases, showing active iteration while leaving little evidence of long-term stability.
All recent commits came from one contributor, creating a concentration risk; organization ownership provides some handoff capacity but no second active contributor is shown.
Only one commit was recorded in the last three months and only one maintainer was active, leaving limited evidence of sustained maintenance beyond the rapid release history.
Composer is used for builds, but no security scanning tools were detected, leaving a modest tooling gap for supply-chain transparency.
The repository has no security policy, so the process for reporting and handling vulnerabilities is unclear.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lattice-php/ui Version self.version | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
lattice-php/core Version self.version | — | — |
lattice-php/form Version self.version | — | — |
illuminate/routing Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.