Tests, a changelog, release notes, and a clear MIT license provide useful maintenance and usage evidence. The repository is not archived, but activity has stopped and its automation has a high-confidence bot-condition warning.
53%
Total Score
50
100
83
50
The package runs a post-autoload-dump install-time script. This deserves awareness during installation, but the signal does not show that the script is unsafe or unusually broad.
The repository is owned by an individual rather than an organization, so the single-person project structure provides limited visible backing if maintenance stops.
The package has six releases, but they were concentrated around its launch and none appeared in the last 12 months, which indicates stalled maintenance.
There were no commits and no active maintainers in the last three months, consistent with the package having received no release in the last year and increasing abandonment risk.
There are no new or closed issues or pull requests in the last month, while two pull requests remain open; this is consistent with limited current activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
livewire/livewire Version ^v3.5 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.