A single maintainer and no security policy reduce confidence for a package handling application models. The MIT declaration, tests, and release notes provide a useful baseline for evaluating the code.
55%
Total Score
50
83
75
One registry maintainer leaves the project dependent on a single publisher. The linked repository is also owned by an individual rather than an organization, so there is no visible backing to offset that concentration.
This is the only release, published about eight months ago, with no established release cadence. That limits evidence of sustained maintenance but is not abandonment by itself.
The repository has recorded zero commits and zero active maintainers in the last three months, and its last push was about eight months ago. No newer activity compensates for the short history.
The repository name matches the package, but its README describes Laravel API Guard and instructs users to install laravel-api-guard rather than this package. That raises concern that the documentation or repository contents may not accurately represent the release.
No security policy is present in the repository. This is a transparency and response-process gap, though it is not severe enough on its own to make the release unfit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.