The MIT license, matching repository, and readable installation guidance improve transparency. The package is young, and its ten runtime dependencies add integration surface.
64%
Total Score
67
50
88
75
Ten runtime dependencies, including Laravel, image-processing, API-documentation, and authentication components, create a meaningful integration and update surface for a CMS package.
The package is only 177 days old with 10 releases, showing active early development but limited long-term maintenance history.
One contributor made all commits in the last three months. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only one commit was recorded in the last three months, indicating limited observed development activity even though the repository is not archived.
Composer is used as a build tool, but no security scanning tools were detected, leaving repository-level security hygiene less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/sanctum Version ^4.0 | — | — |
scssphp/scssphp Version ^1.12 | — | — |
laravel/framework Version ^11.0|^12.0 | — | — |
intervention/image Version ^3.0 | — | — |
bacon/bacon-qr-code Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.