The metapackage is clearly documented, licensed, and backed by an organization. Its installation scope is substantial; choose individual NVL packages when the full suite is unnecessary.
62%
Total Score
83
50
88
88
The suite declares 22 runtime dependencies, including the independently published packages it aggregates. This increases adoption and update surface compared with installing only the needed components.
The project is only 47 days old but has published 16 releases, showing active short-term publishing while leaving little evidence of long-term maturity.
The repository records zero commits and zero active maintainers over the last three months. Because the project is only 47 days old and was recently pushed, this is concerning but not conclusive evidence of abandonment.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
No GitHub Actions workflows were present, so no workflow hazards were found; this also provides no evidence of automated testing or release controls.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nvl/csv Version ^2.0 | — | — |
nvl/seo Version ^2.0 | — | — |
nvl/auth Version ^2.0 | — | — |
nvl/core Version ^2.0 | — | — |
nvl/forms Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.