The README is detailed and the release includes notes, while installation has no lifecycle scripts. Only two releases, no commits for about eight months, and the project’s own warning that it is not production-ready make this a risky dependency.
42%
Total Score
25
50
50
The package has only two releases, both published within about 23 minutes, followed by roughly eight months without another release. That short history provides little evidence of sustained maintenance.
There were zero commits and zero active maintainers in the last three months, with the repository last pushed about eight months ago. This is strong evidence that maintenance may have stalled.
There are no new or closed issues in the last month and one open pull request, offering little evidence of active project development or responsiveness.
Composer is used for the build, but no security scanning tooling is present. This is a modest transparency and maintenance concern rather than a standalone reason to reject the package.
The repository has no published security policy, reducing transparency about vulnerability reporting and response expectations for a package used inside applications.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0 || ^12.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.