The MIT license, release notes, and matching organization-backed repository provide useful transparency. No commits in the last three months and no registry releases in over a year weaken maintenance confidence, while a high-confidence workflow condition issue adds a smaller supply-chain hygiene concern.
62%
Total Score
75
100
86
50
The package has 34 releases over roughly three years, but none in the last 12 months; the long release gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months; this is a concrete maintenance warning, only partly offset by the later repository push timestamp.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. Dependabot provides some compensating security tooling but does not replace a policy.
The assessed release is v1.0.0-beta.1 while the registry reports v0.6.12 as latest and does not identify a stable major release, so adoption carries pre-release and version-line uncertainty.
All workflows were analyzed, but every action reference is unpinned and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Its pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
wireui/wireui Version ^2.0 | — | — |
laravel/framework Version ^11.0 | — | — |
livewire/livewire Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.