It has clear documentation, an MIT license, a repository security policy, repository tests, and no install-time scripts. Organization ownership provides some continuity, though the project’s long-term track record is still limited.
68%
Total Score
67
88
100
The package is only 0 days old with two releases and a median interval of about 18 hours, so maintenance and release stability are not yet established.
One contributor accounts for all 30 recent commits. Organization ownership offers some handoff capacity, but no second active contributor is shown to provide redundancy.
The repository has 30 commits in the last 3 months, showing active development, but all activity comes from one maintainer, leaving continuity dependent on a narrow contributor base.
Composer is used as the build tool, but no security scanning tools were detected, leaving a modest tooling gap for a package with database and application code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nvl/seo Version ^2.0 | — | — |
nvl/core Version ^2.0 | — | — |
nvl/content Version ^2.0 | — | — |
nvl/tenancy Version ^2.0 | — | — |
nesbot/carbon Version ^3.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.