The package is well documented, tested, licensed, and backed by frequent releases. Maintenance is concentrated in one active contributor, but organization ownership and recent activity reduce the handoff risk.
86%
Total Score
88
100
94
100
All 17 recent commits came from one contributor, so maintenance continuity depends heavily on a single individual; organization ownership partly compensates for that concentration.
Composer is used for builds, but no security scanning tools were detected; this is a modest transparency gap rather than evidence of unsafe code.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-27621 typicms/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 16.0.0 - 16.1.7, 15.0.0 - 15.0.29, 14.0.0 - 14.0.27, 13.0.0 - 13.0.9 and 0.0.0 - 12.0.5. | 0.0.0 - 12.0.513.0.0 - 13.0.914.0.0 - 14.0.27 +2 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ~13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.