Usable with caveats: it is actively developed and backed by an organization, with a matching repository and substantial test coverage in the source tree. The project is only 53 days old, all recent commits come from one contributor, and it has no security policy.
72%
Total Score
67
100
81
90
The package is young at 53 days but has 54 releases, including releases through the assessment date. That shows strong current activity, though the short history limits evidence of long-term stability.
One contributor made 100% of the 52 recent commits. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown, so contributor continuity remains a genuine concern.
The repository had 52 commits in the last three months, showing strong recent maintenance. All activity came from one active maintainer, which limits redundancy despite the high commit volume.
Composer is used as a build tool, but no security scanning tools are reported. The build setup is present, while automated security coverage is not demonstrated.
No security policy is present in the repository. That is a transparency and vulnerability-reporting gap for a package used in application projects.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
lattice-php/ui Version self.version | — | — |
illuminate/http Version ^11.0 || ^12.0 || ^13.0 | — | — |
lattice-php/core Version self.version | — | — |
lattice-php/form Version self.version | — | — |
illuminate/routing Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.