The MIT license, README, repository tests, and long release history provide a solid consumer and maintenance baseline. Recent activity is narrow, and workflow references are unpinned; organization backing and a clean audit limit the concern.
72%
Total Score
67
100
100
67
All three recent commits came from one contributor, leaving maintenance dependent on a single active individual; organizational ownership provides only partial compensation because no second recent contributor is shown.
There were three commits in the last three months, so the project is active, although the pace is modest for an actively maintained dependency.
The repository has no security policy. This is a transparency and reporting gap, though it is not evidence of unsafe code by itself.
Both workflows were analyzed without high- or medium-severity findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all three action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
konekt/xtend Version ^2.0 | — | — |
nette/schema Version ^1.2.5 | — | — |
illuminate/support Version ^12.61.1|^13.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.