Clear documentation, licensing, and repository tests make the package straightforward to evaluate. Its maintenance history is still too short to establish durable stability, and security scanning is not reported.
67%
Total Score
83
100
88
88
The package is newly published, with only 2 releases and the latest arriving within the last day. That leaves little evidence about sustained maintenance or release reliability.
The repository has 12 commits in the last 3 months, showing active development. However, the short package age means this does not yet demonstrate sustained maintenance.
Composer build tooling is present, but no security-scanning tool is reported. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
No GitHub Actions workflows were analyzed, so there are no workflow findings, but this also provides no evidence of automated build or security checks.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nvl/core Version ^2.0 | — | — |
nesbot/carbon Version ^2.72 || ^3.0 | — | — |
laravel/framework Version ^13.0 | — | — |
spatie/laravel-data Version ^4.23 | — | — |
spatie/typescript-transformer Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.