Risky to adopt: this package has had only one release, has not seen a release since July 2022, and shows no recent commit activity. It is also explicitly marked not ready for production, despite having tests, documentation, and a clear license.
38%
Total Score
25
71
50
There has been only one release, on July 9, 2022, with no releases in the last 12 months. That long period without published updates is a substantial maintenance and compatibility concern.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old registry release, this indicates a meaningful abandonment risk.
One workflow uses pull_request_target for Dependabot auto-merge. Although no untrusted checkout or script injection was detected, this privileged workflow warrants review.
The package uses a post-autoload-dump lifecycle script, which adds install-time behavior and deserves review before adoption. The signal does not by itself show that the behavior is unsafe.
One registry publishing maintainer is consistent with a small user-owned project, but it leaves the package dependent on a very narrow maintenance base. No stronger organizational backing is present.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^3.4 | — | — |
laravel/cashier Version ^13.11 | — | — |
livewire/livewire Version ^2.10 | — | — |
illuminate/support Version ^9.0 | — | — |
illuminate/contracts Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.