Clear MIT licensing and a matching source tree support straightforward adoption. The missing security policy and scanning reduce transparency for a framework package.
62%
Total Score
67
88
50
The package has a long history and 133 releases, but only two releases in the last 12 months, indicating a currently slow release cadence.
All recent commits came from one contributor, creating a thin operational base; organization ownership provides some handoff capacity but does not replace observed contributor diversity.
Only one commit was recorded in the last three months, with one active maintainer, so recent maintenance activity is limited.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and maintenance-hygiene gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bkwld/cloner Version ^3.9 | — | — |
umomega/tags Version ^1.0 | — | — |
nuclear/reactor Version ^1.0 | — | — |
laravel/framework Version ^9.0 | — | — |
umomega/foundation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.