Usable with caveats: it is a young package with recent releases and active source changes, but all recent commits come from one contributor. The repository has no security policy or security scanning, so adoption should include normal review and monitoring.
68%
Total Score
67
100
79
83
The registry namespace and repository are both owned by the same individual account, and the repository is not organization-backed. This is consistent ownership, but it provides limited redundancy for long-term maintenance.
The package is only 34 days old, but it has had 9 releases, including releases within the last month. This shows active early development, though there is not yet a long maintenance record.
One contributor made all 9 commits in the last 3 months, creating a substantial single-maintainer continuity risk. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to offset that concentration.
The repository has 0 stars, forks, and watchers, providing no supporting evidence of community adoption or external review. Popularity is only supporting evidence, so this lowers confidence more than it determines the verdict.
Composer is used as the build tool, but no security-scanning tools are present. The missing scanning is a transparency and maintenance gap, although it is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.