The README, tests, MIT license, and release notes make the package straightforward to evaluate and adopt. Two unpinned workflow actions, no security policy, and a single registry maintainer leave some maintenance and build-hygiene concerns.
68%
Total Score
67
100
88
67
Only one account has registry publish access, which creates a thin publishing base. The linked repository is also user-owned rather than organization-backed, so no organizational support is evident.
The repository recorded zero commits and zero active maintainers in the last three months. A same-day release provides some counterevidence, but the recent development gap still lowers confidence in ongoing maintenance.
Composer is used for the build, but no security-scanning tools are configured, leaving a modest transparency and hygiene gap.
The repository has no security policy, so users have no documented reporting process for security issues.
Version 0.1.0 is not marked as a prerelease, but the project remains below a stable major version, so its compatibility maturity is somewhat limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
laravel/framework Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.