Healthy and suitable to use, with some project-maturity caveats. It has recent releases, active commits from two contributors, tests, a README, and organization backing, but it is only 42 days old and its workflows lack explicit token permissions and a security policy.
78%
Total Score
88
100
83
80
The package is very new at 42 days old, but it already has six releases, including six in the last 12 months, showing active early development rather than abandonment.
One contributor made 8 of 9 recent commits, creating concentration risk. The second contributor remains active, and organization ownership provides some ability to hand maintenance off.
The repository has zero stars, forks, and watchers. This is weak supporting evidence and is understandable for a package only 42 days old, but it provides little independent community validation.
Composer is used as a build tool, but no security-scanning tool is reported. This is a transparency and assurance gap, though it is not evidence that the package is unsafe.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, although the package is backed by an organization and remains actively maintained.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^4.0 | — | — |
liberusoftware/theme-support Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.