The MIT license, readable README, and repository match make the package transparent to inspect. A missing security policy is a smaller governance gap, but the maintenance evidence remains weak.
43%
Total Score
75
83
50
The package has 10 releases with a fast median interval of about 2 days, but none were published in the last 12 months and the latest release was on September 4, 2025. The earlier release cadence does not compensate for the current year-long gap.
There were no commits and no active maintainers in the last 3 months. Combined with no registry releases in the last 12 months, this is meaningful evidence of stalled maintenance.
The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but this offers no additional evidence of maturity or community adoption.
The repository uses Composer for its build tooling, which fits the package ecosystem. No security scanning tools were detected, leaving security maintenance less visible.
The repository has no security policy. That weakens disclosure and maintenance transparency, though it is a governance gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
superconductor/rpc Version ^0.3.0 | — | — |
spatie/laravel-data Version ^4.11 | — | — |
lorisleiva/laravel-actions Version ^2.6 | — | — |
projectsaturnstudios/quickuuid Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.