The package has clear licensing, a substantial documented file tree, and release notes for this version. Its security process is less transparent, so ongoing ownership deserves attention.
62%
Total Score
50
50
94
88
Seven runtime dependencies, including Laravel, Livewire, and image-processing packages, create a meaningful dependency surface for this UI kit. The profile is plausible for the package's stated framework integration, so this is only a modest concern.
The repository is owned by a user account rather than an organization. This provides less visible institutional backing, while the matching registry and repository namespace still identify a consistent owner.
There have been 36 releases over about 14 months, including 11 in the last year, but the median interval is only about 3 minutes and the latest release was about 7 months ago. This suggests releases were clustered rather than consistently maintained.
The repository had zero commits and zero active maintainers in the last 3 months. Combined with the release-history gap, this is evidence of currently weak maintenance activity.
No repository security policy was found. That reduces transparency for reporting and handling vulnerabilities, though it is not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/volt Version ^v1.6.0 | — | — |
nanodepo/apex Version ^v2.2 | — | — |
laravel/framework Version ^v12.0 | — | — |
livewire/livewire Version ^3.0 | — | — |
intervention/image Version ^3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.