The project includes tests, a readable package, and an MIT license, with organization backing. Its single registry maintainer, absent security policy, and unpinned workflow actions leave less protection as maintenance slows.
61%
Total Score
67
92
50
Only one account has registry publish access, which creates a limited publishing succession path. The organization-owned repository provides some compensation, so this is a concern rather than a severe risk.
The package has three releases, all within its first 8 days, but no release since February 27, about 7 months ago. That short burst followed by a long pause raises maintenance concern for a package still only about 7 months old.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the registry's lack of releases since February. This is a meaningful abandonment risk despite the project's recent origin.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities. This weakens transparency, although it does not by itself indicate unsafe code.
The single workflow was fully analyzed with no untrusted triggers, injection findings, or excessive top-level permissions, but all 3 action references are unpinned. That leaves avoidable build-integrity exposure and warrants a hygiene deduction.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.