Frequent releases and organization ownership provide useful continuity. The alpha status, absent security policy, and unpinned workflow reference add avoidable maintenance and release-process risk.
62%
Total Score
67
50
81
83
Fourteen runtime dependencies, including Laravel, media, activity, search, permission, and state packages, create meaningful compatibility and update surface, though this is plausible for an e-commerce core.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README is a minor integration and transparency gap for a Laravel library.
One contributor made 100% of the two recent commits. Organization ownership provides some handoff capacity, but no second active contributor is shown to demonstrate it.
Only two commits were recorded in the last three months, all from one active maintainer, which is thin recent maintenance evidence compared with the package's release frequency.
Composer build tooling is present, but no security-scanning tooling was detected, leaving automated dependency or code-risk checks unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/scout Version ^10.13.1 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
lunarphp/nestedset Version ^1.0 | — | — |
spatie/laravel-blink Version ^1.7.1 | — | — |
lukascivil/treewalker Version 0.9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.