It has a clear MIT license, a focused file tree, repository tests, and no install-time scripts. The workflow uses read-only permissions but leaves all three actions unpinned, and no security policy is published.
64%
Total Score
50
100
86
67
The package and repository are owned by the same individual account, confirming ownership alignment but providing no organizational maintenance buffer.
This is the package's first release and it was published very recently, so there is not yet enough history to demonstrate sustained maintenance.
All recent commits came from one contributor, leaving maintenance dependent on a single person and creating a meaningful continuity risk.
Only two commits from one active maintainer were recorded in the last three months; for a newly published package this is limited evidence of ongoing maintenance rather than proof of abandonment.
The repository has no published security policy, leaving reporting and response expectations undocumented for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^1.0 | — | — |
laravel/pulse Version ^1.8 | — | — |
livewire/livewire Version ^3.8.3|^4.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.