The package has no security policy or automated security scanning, and its install/update scripts deserve review. Its license and repository linkage are clear, while the source is being changed frequently.
68%
Total Score
67
50
88
67
Twenty runtime dependencies create substantial coupling and increase the maintenance surface compared with a small library. The signal provides no evidence that these dependencies are unmanaged, so this is a moderate concern rather than a severe risk.
The package runs post-create-project-cmd and post-update-cmd scripts, giving installation and update operations extra behavior that should be understood before adoption.
The published artifact has no README, which reduces integration guidance for a library package. Missing tests and changelog files in the artifact are normal packaging practice and do not add concern.
The repository is owned by an individual rather than an organization, so the single-contributor maintenance concentration is not offset by visible organizational backing.
All 171 recent commits came from one contributor, so maintenance depends entirely on a single person with no demonstrated handoff capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.28 | — | — |
brick/money Version ^0.11.2 | — | — |
spatie/invade Version ^2.1 | — | — |
livewire/blaze Version ^1.0 | — | — |
illuminate/view Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.