The package includes a substantial README, tests, release notes, and read-only workflow permissions. MIT licensing, organization backing, and active security tooling improve transparency, but the short history limits evidence of long-term stability.
70%
Total Score
83
88
50
The package is only 61 days old with two releases, so its maintenance record is still limited despite a recent second release.
Two contributors are present, but one accounts for 92.3% of recent commits; organization backing provides some handoff capacity but does not remove the concentration concern.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
v0.2.1 is not a stable-major release, which signals an API that may still change; it is not marked as a prerelease.
The single analyzed workflow has read-only permissions, no untrusted triggers or audit findings, and complete coverage; however, both action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^0.9 | — | — |
illuminate/bus Version ^12.0|^13.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
laravel/prompts Version ^0.3.6 | — | — |
smalot/pdfparser Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.