The package is only 47 days old, so its long-term maintenance record is still unproven. Rapid releases and an active, organization-backed repository help, while the 22-package dependency bundle increases upgrade exposure.
68%
Total Score
67
50
88
100
This metapackage brings in 22 runtime dependencies, so consumers inherit a broad upgrade and compatibility surface. That scope is inherent to a suite but still raises maintenance exposure.
The registry lists one publishing maintainer, which is a limited visible publishing base. The organization-backed repository provides some compensation, so this is not a severe concern.
The package is only 47 days old, but it has 15 releases, including a release within the collection window. This shows active publishing while leaving little evidence of long-term maintenance.
No commits or active maintainers were recorded in the last three months. Because the package is only 47 days old and was pushed on the collection date, this is weak evidence of a problem but leaves sustained maintenance unproven.
The repository uses Composer, appropriate for this package, but no security-scanning tools were detected. That is a modest transparency and hygiene gap, not evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nvl/csv Version ^2.0 | — | — |
nvl/seo Version ^2.0 | — | — |
nvl/auth Version ^2.0 | — | — |
nvl/core Version ^2.0 | — | — |
nvl/forms Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.