It has a clear README, an MIT license, and a repository that matches the package and organization backing. The workflow audit found no dangerous sinks, but its actions are unpinned and the project has no security policy.
42%
Total Score
67
50
79
83
The six-release history stops on September 27, 2023, with no releases in the last 12 months and a package age of about 3 years 6 months. This is strong evidence of abandonment risk despite the stable v2.0.0 release.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release history showing no releases since September 2023. The repository is not archived, but current maintenance capacity is absent.
Six runtime dependencies, including Laravel database components and Netflex libraries, create a meaningful dependency surface for a framework integration. The profile is coherent for this package type but adds maintenance coupling.
Composer build tooling is present, but no security-scanning tools are reported. This is a transparency and maintenance weakness, though it is secondary to the absence of recent development activity.
The repository has no security policy. That makes vulnerability reporting and response expectations unclear, adding a transparency gap for a database integration package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netflex/api Version ^4.0 | — | — |
netflex/dbal Version ^3.0 | — | — |
illuminate/support Version ^10.0 | — | — |
illuminate/database Version ^10.0 | — | — |
netflex/query-builder Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.