The repository is identifiable and organization-backed, with a clear README, MIT licensing, and a GitHub release. It has no tests or security scanning, so future compatibility and maintenance are less visible.
58%
Total Score
75
100
86
50
This is the package's only release, published about 15 months ago, with no releases in the last 12 months. That limited history makes long-term maintenance uncertain.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that has been inactive since its initial release. Organization backing provides context but does not offset the absent recent activity.
Composer is used as a build tool, which fits the package ecosystem. No security scanning is configured, leaving a minor transparency gap rather than evidence of unsafe behavior.
The repository has no security policy. For a small UI package this is a modest transparency gap, but it reduces clarity about vulnerability reporting and response.
No GitHub Actions workflows were present, so there are no workflow risks or unpinned actions to flag. The audit covered all zero workflows successfully; this also means there is no automated build or security validation shown.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.