The project has clear documentation, tests in the repository, an MIT license, and organization backing. Its small audience and missing security policy add modest concerns, while the recent release is not matched by recent commit activity.
67%
Total Score
75
100
81
50
The package runs a post-autoload-dump lifecycle script during Composer installation. This is a real installation-time behavior that deserves review, although the signal does not show that it is unsafe.
The repository recorded zero commits and zero active maintainers in the last 3 months. Although the repository was recently pushed, the observed commit window still indicates weak ongoing development activity.
The repository has 2 stars, 0 forks, and 1 watcher. This indicates a very small user community, but popularity is supporting evidence rather than a health verdict on its own.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance concern.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, which is a minor concern for a reusable UI package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^12.69 | — | — |
gehrisandro/tailwind-merge-laravel Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.