Tests, release notes, and a clear MIT declaration provide useful maintenance and licensing context. The package remains early-stage, with limited outside review and no documented security-reporting process.
72%
Total Score
67
100
93
83
The repository is owned by an individual user rather than an organization, so the concentrated contributor activity is not offset by visible organizational handoff capacity.
One contributor made all 16 recent commits, leaving maintenance heavily dependent on a single person and reducing resilience if that person stops maintaining it.
The repository has no security policy, so users have no documented reporting path; this is a transparency gap, though it does not establish abandonment.
v0.5.0 is not a prerelease, but the 0.x major version indicates an API that may still change materially compared with a mature 1.x package.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Both of its two action references are unpinned, which is a supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^3.0|^4.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.