The package includes tests, a substantial README, and release notes, but its single maintainer and inactive release history reduce confidence. Workflow images are unpinned, and no security policy is provided, so ongoing maintenance and build hygiene need scrutiny.
62%
Total Score
50
100
81
75
Only one registry account has publish access, which creates a thin publishing base for a user-owned project. The matching repository owner supports accountability but does not provide contributor redundancy.
The registry namespace and repository are owned by the same individual, so the package has clear ownership but no organization-backed maintainer capacity.
The package has 10 releases over about four and a half years, but none in the 12 months before the latest September 2024 release. That suggests maintenance may have stopped, despite the earlier short median release interval.
Composer build tooling is present, but no security-scanning tooling is reported. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
The repository has no security policy. For a package used in application code, this weakens the documented path for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^8.62|^9.0.0|^11.20 | — | — |
inertiajs/inertia-laravel Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.