Usable with caveats: the project is actively developed, licensed, and not deprecated or archived, but it is still an early 0.x release with one active contributor. The package has no README, its repository README does not mention the package, and no security policy is present.
68%
Total Score
80
100
75
83
Only one registry account can publish releases, which creates publishing continuity risk; the organization-backed repository partly compensates for this narrow registry access list.
The published artifact has no README, which is a real documentation gap for a framework consumers must integrate against; the absence of packaged tests and changelog is normal packaging practice and is not penalized.
All 65 recent commits came from one contributor, creating a meaningful continuity risk; organization ownership provides some ability to hand maintenance to another contributor but no second active contributor is shown.
The repository name matches the package name, which supports the linkage, but its README does not mention the package, leaving some uncertainty about package-specific documentation and ownership context.
Composer build tooling is present, but no security scanning tool was detected, leaving a transparency and maintenance-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
roots/acorn Version ^6.2 | — | — |
symfony/uid Version ^8.1.0 | — | — |
livewire/livewire Version ^4.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.