Clear licensing, documentation, repository tests, and an active security policy improve confidence. The organization-backed repository is maintained, but it is less than a day old and all recent commits come from one contributor.
68%
Total Score
67
100
88
100
The package is less than a day old with only two releases, so there is not yet enough history to demonstrate sustained maintenance or release stability.
All 17 recent commits came from one contributor, leaving a thin practical maintainer base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has 17 commits in the last three months, showing active work, but that activity is concentrated in a very new project and does not yet establish long-term maintenance.
Composer build tooling is present, but no security scanning tools are reported. This is a modest supply-chain hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nvl/core Version ^2.0 | — | — |
nvl/tenancy Version ^2.0 | — | — |
nesbot/carbon Version ^2.72 || ^3.0 | — | — |
laravel/framework Version ^13.0 | — | — |
spatie/laravel-data Version ^4.23 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.