The repository has no commits or active maintainers in the last three months, and its README does not identify this package. Licensing, release notes, and organization backing provide some transparency, but the release history is too thin for a dependable 2.0.0.
44%
Total Score
50
58
75
Only two releases exist, both from August 2022, with no releases in the last 12 months. That long gap materially raises abandonment risk for a package being assessed at version 2.0.0.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository was pushed recently, the observed development activity is too limited to demonstrate ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. That raises concern that the linked repository may not actually be the source for this release.
The linked repository has no security policy. This is a transparency and maintenance gap, though it is less significant than the stale release history and unclear package-to-repository relationship.
The assessed version is 2.0.0, while the registry reports 1.0.1 as the latest version. This inconsistency weakens confidence that the release metadata and publication history are coherent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
backpack/crud Version ^5.0 | — | — |
illuminate/contracts Version ^9.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
spatie/laravel-schedule-monitor Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.