Repository tooling and its security policy are reassuring, while the stable version and MIT license reduce adoption friction. Inactive issues and commits, plus unpinned workflow actions, warrant caution before adopting this release.
57%
Total Score
67
50
94
100
The package declares 14 runtime dependencies, including framework, payment, admin, and Livewire components. This is a substantial integration surface that can increase compatibility and maintenance burden.
The package has 84 releases, but its latest registry release was more than five years ago and there were no releases in the last 12 months. This is a material maintenance concern despite the historically frequent release cadence.
There were no commits and no active maintainers in the last three months. Although the repository was pushed in August 2025, current development activity remains unverified and appears inactive.
The repository has 10 open issues and one open pull request, but no new or closed issues or pull requests in the last month. This suggests limited current issue-management activity.
All three workflows were analyzed without high-confidence findings, dangerous triggers, untrusted checkouts, or script injection. However, all seven action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^3.22 | — | — |
nesbot/carbon Version ^2.44 | — | — |
beberlei/assert Version ^3.3.1 | — | — |
cakephp/chronos Version ^1.2.3|^2.1.2 | — | — |
laravel/cashier Version ^12.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.