The package has clear documentation, tests, a matching source repository, and a recent release with explicit migration notes. Its small maintainer base and missing security-policy and workflow permission declarations leave less operational assurance than a mature project.
62%
Total Score
63
100
94
80
Only one account has registry publishing access. That is a limited publishing base for a user-owned project and increases continuity risk if the maintainer becomes unavailable.
The registry namespace and repository owner match, but both are a personal user account rather than an organization, so there is no visible organizational continuity buffer.
The repository recorded zero commits and zero active maintainers during the past three months. The recent v2.0.0 release provides some compensating evidence, but current maintenance activity is still thin.
The repository has 6 stars, 0 forks, and 1 watcher, indicating limited adoption. Popularity is supporting evidence rather than a decisive health measure for a small package.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it does not by itself show an unsafe release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.2|^8.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/database Version ^12.0|^13.0 | — | — |
spatie/laravel-markdown Version ^2.5 | — | — |
spatie/yaml-front-matter Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.