The package has a long release history and a stable version, with a matching organization-backed repository and no deprecation. Recent repository activity is absent, and workflow permissions, unpinned actions, and missing security scanning leave maintenance and build-hygiene concerns.
70%
Total Score
83
100
94
67
The repository recorded zero commits and zero active maintainers in the last 3 months, which weakens evidence of ongoing maintenance despite the recent release.
Composer build tooling is present, but no security-scanning tool was detected, leaving repository security hygiene less transparent.
The repository has no security policy, reducing the clarity of its vulnerability-reporting process.
The single workflow uses a pull_request_target trigger without an untrusted checkout or script-injection sink, but it grants top-level write permissions and uses its only action unpinned. These are moderate workflow-hygiene concerns, not severe evidence on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netflex/api Version ^7.0 | — | — |
netflex/pages Version ^7.0 | — | — |
laravel/framework Version ^13.0 | — | — |
netflex/foundation Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.